VDB
Sign up
HIGH

GHSA-qwp9-52h8-xgg8

Prototype pollution in JointJS

Quick fix

GHSA-qwp9-52h8-xgg8 — jointjs: upgrade to the fixed version with the command below.

npm install jointjs@3.3.0

Details

The package jointjs before 3.3.0 are vulnerable to Prototype Pollution via util.setByPath (https://resources.jointjs.com/docs/jointjs/v3.2/joint.htmlutil.setByPath). The path used the access the object's key and set the value is not properly sanitized, leading to a Prototype Pollution.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jointjs
Introduced in: 0Fixed in: 3.3.0
Fixnpm install jointjs@3.3.0

References