Prototype Pollution Vulnerability Affecting fast-loops module, versions [1.1.1, 1.1.3] #18
Closed
Description
Overview
A Prototype Pollution vulnerability Affecting fast-loops, versions >=1.1.1, <=1.1.3, due to missing check if the argument resolves to the object prototype. This allow the attacker to inject malicious object property using the built-in Object property proto which recursively assigned to all the objects in the program.
Details sent directly to the maintainers.
Metadata
Assignees
Labels
No labels