altair-graphql-core is vulnerable to Prototype Pollution
70
High Risk
Affected versions of this package are vulnerable to Prototype Pollution vulnerability in the setByDotNotation utility function, where the lack of validation for user-controlled dot-notation paths allows an attacker to exploit it by injecting dangerous keys like __proto__, constructor, or prototype to mutate Object.prototype, potentially leading to Denial of Service (DoS), logic bypasses, or even Remote Code Execution (RCE).
You are affected if you are using a version that falls within the vulnerable range.
altair-graphql-core is vulnerable to Prototype Pollution in versions 7.2.0 - 8.4.1.
Upgrade the altair-graphql-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant