HIGH7.5
GHSA-pfv6-prqm-85q8
Prototype Pollution in madlib-object-utils
Quick fix
GHSA-pfv6-prqm-85q8 — madlib-object-utils: upgrade to the fixed version with the command below.
npm install madlib-object-utils@0.1.8Details
The package madlib-object-utils before version 0.1.8 is vulnerable to Prototype Pollution via the `setValue` method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix of [CVE-2020-7701](https://security.snyk.io/vuln/SNYK-JS-MADLIBOBJECTUTILS-598676)
Are you affected?
Enter the version of the package you're using.