VYPR

npm package

steal

pkg:npm/steal

Vulnerabilities (8)

  • CVE-2022-37265Sep 20, 2022
    affected <= 2.3.0

    Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.

  • CVE-2022-37259Sep 20, 2022
    affected <= 2.3.0

    A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the string variable in babel.js.

  • CVE-2022-37258Sep 16, 2022
    affected <= 2.3.0

    Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js.

  • CVE-2022-37260Sep 15, 2022
    affected <= 2.3.0

    A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the input variable in main.js.

  • CVE-2022-37264Sep 15, 2022
    affected <= 2.3.0

    Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js.

  • CVE-2022-37262Sep 15, 2022
    affected <= 2.3.0

    A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the source and sourceWithComments variable in main.js.

  • CVE-2022-37257Sep 15, 2022
    affected <= 2.3.0

    Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.

  • CVE-2022-37266Sep 15, 2022
    affected <= 2.3.0

    Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js.