@intlify/shared is vulnerable to Prototype Pollution
80
High Risk
The latest version of @intlify/shared is vulnerable to Prototype Pollution through the lib.deepCopy function. An attacker can craft a payload that modifies the global prototype chain by adding or altering properties, leading to a Denial of Service (DoS) as a minimum impact. If the polluted properties affect sensitive areas of the application, such as Node.js APIs (exec, eval), the vulnerability can escalate to arbitrary command execution, posing a severe security risk.
You are affected if you are using a version that falls within the vulnerable range.
@intlify/shared is vulnerable to Prototype Pollution in versions 9.3.0 - 9.14.1 and 10.0.0 - 10.0.4.
Upgrade the @intlify/shared library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant