VYPR

Nested Object Assign

by Getadigital

CVEs (1)

  • CVE-2021-23329HigJan 31, 2021
    risk 0.00cvss 7.5epss 0.02

    The package nested-object-assign before 1.0.4 are vulnerable to Prototype Pollution via the default function, as demonstrated by running the PoC below.