re2js is vulnerable to Prototype Pollution
72
High Risk
Affected versions of this package are affected by a Prototype Pollution vulnerability in the getNamedGroups method, where an ordinary object was created with {} and could inherit or interact with dangerous prototype properties. By supplying specially crafted group names such as __proto__, constructor, or prototype, an attacker may be able to pollute the object prototype chain, causing unexpected property injection, application logic manipulation, denial of service, or unsafe behavior in downstream code that trusts the returned object.
You are affected if you are using a version that falls within the vulnerable range.
re2js is vulnerable to Prototype Pollution in versions 2.1.0 - 2.1.0.
Upgrade the re2js library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant