@pdfme/common is vulnerable to Prototype Pollution
75
High Risk
Affected versions of this package are vulnerable to prototype pollution through the replacePlaceholders function. An attacker can manipulate object properties via crafted input, potentially leading to unexpected behavior or security bypasses. The patch addresses this by implementing robust input sanitization and safe property assignment to prevent unauthorized modification of object prototypes, while also strengthening protection against cross-site scripting (XSS) through improved data handling.
You are affected if you are using a version that falls within the vulnerable range.
@pdfme/common is vulnerable to Prototype Pollution in versions 5.2.0 - 5.4.0.
Upgrade the @pdfme/common library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant