VYPR

Bodymen

by Bodymen Project

CVEs (2)

  • CVE-2022-25296MedMar 17, 2022
    risk 0.41cvss 6.3epss 0.01

    The package bodymen from 0.0.0 are vulnerable to Prototype Pollution via the handler function which could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. **Note:** This vulnerability derives from an incomplete fix to…

  • CVE-2019-10792MedFeb 18, 2020
    risk 0.34cvss 6.3epss 0.01

    bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.