CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.
All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.
All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.
All versions of package deeps are vulnerable to Prototype Pollution via the set function.
All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.
All versions of package confucious are vulnerable to Prototype Pollution via the set function.
All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.
This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
