-
Notifications
You must be signed in to change notification settings - Fork 513
huntr.dev - Prototype Pollution #340
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Issue already reported at #339. |
Brilliant, I have seen you have also referenced the pull request as well in the issue! 🍰 |
@jotamorais This issue may be closed in favor of #339. |
This issue has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs. |
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Vulnerability Description
Affected versions of this package are vulnerable to Prototype Pollution. the
classToPlainFromExist
function could be tricked into adding or modifying properties ofObject.prototype
using a__proto__
payload.Steps To Reproduce:
Bug Bounty
We have opened up a bounty for this issue on our bug bounty platform. Want to solve this vulnerability and get rewarded 💰? Go to https://huntr.dev/
The text was updated successfully, but these errors were encountered: