VDB
Sign up
MEDIUM6.3

GHSA-vhxc-fhm5-qcp9

Prototype Pollution in bodymen

Details

The package bodymen from 0.0.0 are vulnerable to Prototype Pollution via the handler function which could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. **Note:** This vulnerability derives from an incomplete fix to [CVE-2019-10792](https://security.snyk.io/vuln/SNYK-JS-BODYMEN-548897)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bodymen
Introduced in: 0.0.0

No fixed version published yet for bodymen (npm). Pin to a known-safe version or switch to an alternative.

References