Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22715
HistoryMar 17, 2020 - 4:41 a.m.

Prototype Pollution

2020-03-1704:41:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20

EPSS

0

Percentile

12.8%

yargs-parser is vulnerable to prototype pollution. The attack exists as it does not properly sanitize the key value provided by users, allowing the malicious properties of Object.prototype to be parsed or modified using a __proto__ payload.