MEDIUM5.3
GHSA-jgpq-g82g-6c39
confinit vulnerable to prototype pollution
Quick fix
GHSA-jgpq-g82g-6c39 — confinit: upgrade to the fixed version with the command below.
npm install confinit@0.4.0Details
confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
Are you affected?
Enter the version of the package you're using.