npm package
@conform-to/dom
pkg:npm/%40conform-to/dom
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-32866 | Hig | 8.6 | >= 1.0.0, < 1.1.1 | 1.1.1 | Apr 23, 2024 | Conform, a type-safe form validation library, allows the parsing of nested objects in the form of `object.property`. Due to an improper implementation of this feature in versions prior to 1.1.1, an attacker can exploit the feature to trigger prototype pollution by passing a craft |
- affected >= 1.0.0, < 1.1.1fixed 1.1.1
Conform, a type-safe form validation library, allows the parsing of nested objects in the form of `object.property`. Due to an improper implementation of this feature in versions prior to 1.1.1, an attacker can exploit the feature to trigger prototype pollution by passing a craft