Описание
CASL Ability is Vulnerable to Prototype Pollution
CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-1774
- https://github.com/stalniy/casl/pull/1093
- https://github.com/stalniy/casl/commit/39da920ec1dfadf3655e28bd0389e960ac6871f4
- https://cwe.mitre.org/data/definitions/1321.html
- https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/Prototype_pollution
- https://github.com/stalniy/casl/tree/master/packages/casl-ability
- https://www.kb.cert.org/vuls/id/458422
Пакеты
Наименование
@casl/ability
npm
Затронутые версииВерсия исправления
>= 2.4.0, <= 6.7.4
6.7.5
Связанные уязвимости
nvd
2 дня назад
CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.