Lucene search

K
nodejsAsgerfNODEJS:722
HistoryNov 05, 2018 - 5:04 p.m.

Prototype Pollution

2018-11-0517:04:20
asgerf
www.npmjs.com
11

0.001 Low

EPSS

Percentile

45.1%

Overview

Versions of merge before 1.2.1 are vulnerable to prototype pollution. The merge.recursive function can be tricked into adding or modifying properties of the Object prototype.

Recommendation

Update to version 1.2.1 or later.

References

CPENameOperatorVersion
mergele1.2.0