Описание
Prototype Pollution in open-graph
This affects the package open-graph before 0.2.6. The function parse could be tricked into adding or modifying properties of Object.prototype using a proto or constructor payload.
Пакеты
Наименование
open-graph
npm
Затронутые версииВерсия исправления
< 0.2.6
0.2.6
Связанные уязвимости
CVSS3: 7.3
nvd
больше 4 лет назад
This affects the package open-graph before 0.2.6. The function parse could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor payload.