VYPR

npm package

msgpack5

pkg:npm/msgpack5

Vulnerabilities (1)

  • CVE-2021-21368Mar 12, 2021
    affected < 3.6.1fixed 3.6.1

    msgpack5 is a msgpack v5 implementation for node.js and the browser. In msgpack5 before versions 3.6.1, 4.5.1, and 5.2.1 there is a "Prototype Poisoning" vulnerability. When msgpack5 decodes a map containing a key "__proto__", it assigns the decoded value to __proto__. Object.pro