CRITICAL9.8
GHSA-wjc4-73q6-gv3m
plotly.js prototype pollution vulnerability
Quick fix
GHSA-wjc4-73q6-gv3m — plotly/plotly.js: upgrade to the fixed version with the command below.
composer require plotly/plotly.js:^2.25.2Details
In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/plotly/plotly.js
Introduced in:
0Fixed in: 2.25.2Fix
composer require plotly/plotly.js:^2.25.2References
- https://nvd.nist.gov/vuln/detail/CVE-2023-46308[ADVISORY]
- https://github.com/plotly/plotly.R/issues/2463[WEB]
- https://github.com/plotly/plotly.js/commit/02498404c8ad7a3395191e65694fb142a37b0fe9[WEB]
- https://github.com/plotly/plotly.js/commit/5efd2a1f07a418b230a5626fc6c1c7929c47949d[WEB]
- https://github.com/plotly/plotly.js[PACKAGE]
- https://github.com/plotly/plotly.js/releases/tag/v2.25.2[WEB]
- https://plotly.com/javascript[WEB]