VYPR

Json8 Merge Patch

by Json8 Merge Patch Project

CVEs (1)

  • CVE-2020-8268HigNov 9, 2020
    risk 0.42cvss 7.5epss 0.01

    Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.