protobufjs is vulnerable to Prototype Pollution
55
Medium Risk
Affected versions of this package are vulnerable to prototype pollution due to unsafe handling of the proto property during message initialization. The Message constructor processes user-controlled input objects and assigns their fields onto the message instance without restricting special keys, allowing attackers to supply a proto property that modifies the prototype of the created object. This can lead to prototype chain manipulation and unintended property injection across the application when polluted objects are later used.
You are affected if you are using a version which is within vulnerability ranges.
protobufjs is vulnerable to Prototype Pollution in versions 0.0.1 - 8.0.0.
Upgrade the protobufjs library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant