VYPR
High severityNVD Advisory· Published Jan 31, 2021· Updated Sep 16, 2024

Prototype Pollution

CVE-2021-23329

Description

The package nested-object-assign before 1.0.4 are vulnerable to Prototype Pollution via the default function, as demonstrated by running the PoC below.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
nested-object-assignnpm
< 1.0.41.0.4

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.