VDB
Sign up
MEDIUM

GHSA-qrmc-fj45-qfc2

Prototype Pollution in extend

Quick fix

GHSA-qrmc-fj45-qfc2 — extend: upgrade to the fixed version with the command below.

npm install extend@3.0.2

Details

Versions of `extend` prior to 3.0.2 (for 3.x) and 2.0.2 (for 2.x) are vulnerable to Prototype Pollution. The `extend()` function allows attackers to modify the prototype of Object causing the addition or modification of an existing property that will exist on all objects.

## Recommendation

If you're using `extend` 3.x upgrade to 3.0.2 or later. If you're using `extend` 2.x upgrade to 2.0.2 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/extend
Introduced in: 3.0.0Fixed in: 3.0.2
Fixnpm install extend@3.0.2
npm/extend
Introduced in: 1.1.3Fixed in: 2.0.2
Fixnpm install extend@2.0.2

References