VDB
Sign up
CRITICAL9.8

GHSA-vwhq-pm3r-fjm9

steal vulnerable to Prototype Pollution via key variable in babel.js

Details

Prototype pollution vulnerability in function extend in babel.js in stealjs steal via the key variable in babel.js.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/steal
Introduced in: 0

No fixed version published yet for steal (npm). Pin to a known-safe version or switch to an alternative.

References