Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8jq-4rm5-4hm5

Опубликовано: 01 апр. 2025
Источник: github
Github: Прошло ревью
CVSS4: 8.9

Описание

@alizeait/unflatto Prototype Pollution

Impact

alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

Patches

The problem has been patched in 1.0.3

References

https://github.com/advisories/GHSA-799q-f2px-wx8c

Пакеты

Наименование

@alizeait/unflatto

npm
Затронутые версииВерсия исправления

< 1.0.3

1.0.3

EPSS

Процентиль: 59%
0.00378
Низкий

8.9 High

CVSS4

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 9.8
nvd
11 месяцев назад

alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

EPSS

Процентиль: 59%
0.00378
Низкий

8.9 High

CVSS4

Дефекты

CWE-1321