tarteaucitronjs is vulnerable to Prototype Pollution
73
High Risk
Affected versions of this package are vulnerable to prototype pollution due to unsafe property merging in a for...in loop without hasOwnProperty checks, allowing an attacker to inject malicious properties into Object.prototype by crafting an object with keys like __proto__ or constructor.prototype. It can lead to arbitrary code execution, privilege escalation, or denial of service by polluting the prototype chain.
You are affected if you are using a version that falls within the vulnerable range.
tarteaucitronjs is vulnerable to Prototype Pollution in versions 1.8.1 - 1.19.0.
Upgrade the tarteaucitronjs library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant