elysia is vulnerable to Prototype Pollution
71
High Risk
Affected versions of this package are vulnerable to Prototype Pollution because the skipKeys validation in the object assignment loop did not block the specially crafted properties __proto__, constructor, and prototype. An attacker could exploit this by providing a malicious source object containing these properties, allowing them to pollute the global object prototype and potentially modify the application's behavior, crash the program, or achieve remote code execution.
You are affected if you are using a version that falls within the vulnerable range.
elysia is vulnerable to Prototype Pollution in versions 1.1.0 - 1.4.16.
Upgrade the elysia library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant