-
Notifications
You must be signed in to change notification settings - Fork 67
Open
Description
We are getting dependabot alert on version (4.2.3, but does not seemed to be patched in 4.2.4) about minimist.
Could you patch to include Dependabot recommendation please?
Affected versions of
minimist
are vulnerable to prototype pollution. Arguments are not properly sanitized, allowing an attacker to modify the prototype ofObject
, causing the addition or modification of an existing property that will exist on all objects.
Parsing the argument--__proto__.y=Polluted
adds a y property with valuePolluted
to all objects. The argument--__proto__=Polluted
raises and uncaught error and crashes the application.
This is exploitable if attackers have control over the arguments being passed tominimist
.Recommendation
Upgrade to versions 0.2.1, 1.2.3 or later.
radicand, jledentu and crs26
Metadata
Metadata
Assignees
Labels
No labels