yargs is vulnerable to Prototype Pollution
24
Low Risk
mergeDeep in apply-extends recursively merges configuration objects without skipping __proto__ keys. Attacker-influenced config that includes __proto__ can therefore pollute the merged object's prototype and alter later property lookups. The fix skips __proto__ during the deep merge.
You are affected if you are using a version that falls within the vulnerable range and applyExtends / config extends merges attacker-influenced objects.
yargs is vulnerable to Prototype Pollution in versions 0.0.1 - 18.0.0.
Upgrade the yargs library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant