typeson is vulnerable to Prototype Pollution
73
High Risk
Affected versions of this package are vulnerable to prototype pollution via the lib.setAtKeyPath function. An attacker can craft input containing an Object.prototype setter to inject or alter properties on the global prototype chain. This can lead to a denial of service (DoS) at minimum, but the impact can escalate significantly depending on how the library is used within an application. If polluted properties propagate into sensitive Node.js APIs—such as exec or eval—the vulnerability may enable arbitrary command execution in the application's context, resulting in remote code execution or other injection-based attacks.
You are affected if you are using a version that falls within the vulnerable range.
typeson is vulnerable to Prototype Pollution in versions 5.11.0 - 9.0.3.
Upgrade the typeson library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant