VDB
Sign up
HIGH7.5

GHSA-v9mx-4pqq-h232

Bun has an Application-level Prototype Pollution vulnerability in the runtime native API for Glo

Quick fix

GHSA-v9mx-4pqq-h232 — bun: upgrade to the fixed version with the command below.

npm install bun@1.1.30

Details

Versions of the package bun before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun's APIs that accept objects.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bun
Introduced in: 0Fixed in: 1.1.30
Fixnpm install bun@1.1.30

References