VYPR

Component Flatten

by Component Flatten Project

CVEs (1)

  • CVE-2019-10794MedFeb 18, 2020
    risk 0.41cvss 6.3epss 0.01

    All versions of component-flatten are vulnerable to Prototype Pollution. The a function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.