You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It seems that currently a calendar's fields method can return a list that includes constructor and/or __proto__.
I can't think of any use case where these two properties should be calendar fields. If not, should we ban them? It might avoid a class of prototype pollution vulnerabilities as well.
The text was updated successfully, but these errors were encountered:
It seems that currently a calendar's
fields
method can return a list that includesconstructor
and/or__proto__
.I can't think of any use case where these two properties should be calendar fields. If not, should we ban them? It might avoid a class of prototype pollution vulnerabilities as well.
The text was updated successfully, but these errors were encountered: