VYPR

npm package

web3-utils

pkg:npm/web3-utils

Vulnerabilities (1)

  • CVE-2024-21505HigMar 25, 2024
    affected >= 4.0.1, < 4.2.1fixed 4.2.1

    Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all ob