chartist is vulnerable to Prototype Pollution
98
Critical Risk
Affected versions of the chartist package are vulnerable to prototype pollution due to missing validation when assigning object properties. An attacker can exploit this by injecting malicious properties via the __proto__ key, which can recursively pollute the object prototype and affect all objects across the application.
You are affected if you are using a version that falls within the vulnerable range.
chartist is vulnerable to Prototype Pollution in versions 1.0.0 - 1.3.0.
Upgrade the chartist library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant