VDB
Sign up
HIGH8.1

GHSA-p33m-7w7f-gmj8

Uncontrolled Resource Consumption in fun-map

Details

fun-map through 3.3.1 is vulnerable to Prototype Pollution. The function assocInM could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/fun-map
Introduced in: 0

No fixed version published yet for fun-map (npm). Pin to a known-safe version or switch to an alternative.

References