VYPR

npm package

class-transformer

pkg:npm/class-transformer

Vulnerabilities (1)

  • CVE-2020-7637Apr 6, 2020
    affected < 0.3.1fixed 0.3.1

    class-transformer before 0.3.1 allow attackers to perform Prototype Pollution. The classToPlainFromExist function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.