Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
The product does not properly protect an assumed-immutable element from being modified by an attacker.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Json8-merge-patch | Json8-merge-patch_project | * | 1.0.3 (excluding) |