Lucene search

K
osvGoogleOSV:GHSA-V39P-96QG-C8RF
HistorySep 01, 2021 - 6:37 p.m.

Prototype Pollution in object-path

2021-09-0118:37:11
Google
osv.dev
14

0.005 Low

EPSS

Percentile

76.3%

This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition currentPath === '__proto__' returns false if currentPath is ['__proto__']. This is because the === operator returns always false when the type of the operands is different.

CPENameOperatorVersion
object-pathlt0.11.6