CRITICAL9.8
GHSA-wc4x-qmr2-rj8h
steal vulnerable to Prototype Pollution via alias variable
Details
Prototype pollution vulnerability in stealjs steal via the alias variable in babel.js.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/steal
Introduced in:
0No fixed version published yet for steal (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-37265[ADVISORY]
- https://github.com/stealjs/steal/issues/1534[WEB]
- https://github.com/stealjs/steal[PACKAGE]
- https://github.com/stealjs/steal/blob/c9dd1eb19ed3f97aeb93cf9dcea5d68ad5d0ced9/ext/babel.js#L4216[WEB]
- https://github.com/stealjs/steal/blob/c9dd1eb19ed3f97aeb93cf9dcea5d68ad5d0ced9/ext/babel.js#L4569[WEB]