VYPR

Node.extend

by Dreamerslab

CVEs (1)

  • CVE-2018-16491CriFeb 1, 2019
    risk 0.64cvss 9.8epss 0.02

    A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.