xregexp is vulnerable to Prototype Pollution
70
High Risk
The latest version of xregexp (5.1.1) is vulnerable to prototype pollution through the XRegExp.cache function. An attacker can supply a crafted payload with a pattern and flag to manipulate properties within the global prototype chain. This vulnerability can lead to more severe injection-based attacks, depending on how the library is used. For instance, if the polluted property propagates to sensitive Node.js APIs (e.g., exec, eval), an attacker could execute arbitrary commands within the application's context.
You are affected if you are using a version that falls within the vulnerable range.
xregexp is vulnerable to Prototype Pollution in versions 5.0.0 - 5.1.1.
Upgrade the xregexp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant