VYPR

npm package

@eivifj/dot

pkg:npm/%40eivifj/dot

Vulnerabilities (1)

  • CVE-2020-7639MedApr 6, 2020
    affected < 1.0.3fixed 1.0.3

    eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.