VYPR

npm package

taffy

pkg:npm/taffy

Vulnerabilities (1)

  • CVE-2019-10790Feb 17, 2020
    affected <= 2.6.2

    taffydb npm module, vulnerable in all versions up to and including 2.7.3, allows attackers to forge adding additional properties into user-input processed by taffy which can allow access to any data items in the DB. taffy sets an internal index for each data item in its DB. Howev