VYPR

npm package

argencoders-notevil

pkg:npm/argencoders-notevil

Vulnerabilities (1)

  • CVE-2021-23771Mar 17, 2022
    affected <= 2.5.0

    This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing an attacker to add or modify an object's prototype. **N