Описание
Prototype Pollution in mergify
All versions of mergify are vulnerable to Prototype Pollution. The mergify() function allows attackers to modify the prototype of Object causing the addition or modification of an existing property that will exist on all objects.
Recommendation
No fix is currently available. Consider using an alternative module as the package is deprecated.
Пакеты
Наименование
mergify
npm
Затронутые версииВерсия исправления
Отсутствует
Дефекты
CWE-1321
Дефекты
CWE-1321