VDB
Sign up
CRITICAL9.8

GHSA-gvjw-8mmr-8f6g

steal vulnerable to Prototype Pollution

Details

Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/steal
Introduced in: 0

No fixed version published yet for steal (npm). Pin to a known-safe version or switch to an alternative.

References