@marcbachmann/cel-js is vulnerable to Prototype Pollution
73
High Risk
Affected versions of this package are vulnerable to Prototype Pollution through unsafe object creation where the code dynamically assigns properties without validating keys, allowing an attacker to exploit this by crafting malicious input that sets the __proto__, constructor, or prototype keys to pollute the base object prototype, potentially leading to denial of service, privilege escalation, or remote code execution by modifying inherited properties across the application.
You are affected if you are using a version that falls within the vulnerable range.
@marcbachmann/cel-js is vulnerable to Prototype Pollution in versions 2.0.4 - 5.2.0.
Upgrade the @marcbachmann/cel-js library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant