MEDIUM6.5
GHSA-j452-xhg8-qg39
Mafintosh's protocol-buffers-schema is vulnerable to prototype pollution
Quick fix
GHSA-j452-xhg8-qg39 — protocol-buffers-schema: upgrade to the fixed version with the command below.
npm install protocol-buffers-schema@3.6.1Details
JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve remote code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/protocol-buffers-schema
Introduced in:
0Fixed in: 3.6.1Fix
npm install protocol-buffers-schema@3.6.1