VDB
Sign up
CRITICAL9.8

GHSA-x72j-hv9f-qqh4

parse-ini is vulnerable to Prototype Pollution in index.js()

Details

npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/parse-ini

No fixed version published yet for parse-ini (npm). Pin to a known-safe version or switch to an alternative.

References