VYPR

npm package

controlled-merge

pkg:npm/controlled-merge

Vulnerabilities (1)

  • CVE-2020-28268Nov 15, 2020
    affected >= 1.0.0, < 1.3.0fixed 1.3.0

    Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.