csv-parse is vulnerable to Prototype Pollution
63
Medium Risk
Affected versions of this package are vulnerable to prototype pollution when processing user-controlled column or header names. The parser allows nested property paths to be created on plain objects without filtering special keys such as __proto__, constructor, or prototype. A crafted CSV input can therefore inject properties into Object.prototype, causing polluted values to propagate to all subsequently created objects.
You are affected if you are using a version that falls within the vulnerable range.
csv-parse is vulnerable to Prototype Pollution in versions 0.0.1 - 6.2.0.
Upgrade the csv-parse library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant