Intel

AIKIDO-2024-10135

extend2 is vulnerable to Prototype Pollution

Prototype Pollution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 21, 2024

50

Medium Risk

This Affects:

JSextend2
1.0.0 - 1.0.1
Fixed in 4.0.0
Are you affected? Scan for Free

TL;DR

Affected versions of extend2 are vulnerable to a prototype pollution vulnerability via the extend(...) function.

Who does this affect?

You are affected if you use a vulnerable version of extend2 and directly or indirectly use the extend(...) function.

Background info

extend2 is vulnerable to Prototype Pollution in versions 1.0.0 - 1.0.1.

How to fix this

Upgrade extend2 to a patch version.