chartist is vulnerable to Prototype Pollution
98
Critical Risk
Affected versions of the chartist package are vulnerable to prototype pollution due to missing validation when assigning object properties. An attacker can exploit this by injecting malicious properties via the __proto__ key, which can recursively pollute the object prototype and affect all objects across the application.
You are affected if you are using a version that falls within the vulnerable range.
chartist is vulnerable to Prototype Pollution in versions 1.0.0 - 1.3.0.
Upgrade the chartist library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant