moderndash is vulnerable to Prototype Pollution
65
Medium Risk
Affected versions of this package contain a prototype pollution vulnerability in the merge and set functionality, where unsafe handling of __proto__ keys may allow modification of an object’s prototype chain and unintended propagation of attacker-controlled properties across the application. An attacker might exploit this by supplying crafted input containing __proto__ payloads to pollute base objects, potentially altering application logic, bypassing security checks, causing denial of service, or enabling further impact depending on how polluted objects are later used.
You are affected if you are using a version that falls within the vulnerable range.
moderndash is vulnerable to Prototype Pollution in versions 0.7.1 - 4.0.0.
Upgrade the moderndash library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant