An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS0zcTU2LTljYzItNDZqNM4AA9bz

High CVSS: 7.7 EPSS: 0.00205% (0.43068 Percentile) EPSS:

robinweser fast-loops vulnerable to prototype pollution

Affected Packages Affected Versions Fixed Versions
npm:fast-loops < 1.1.4 1.1.4
49 Dependent packages
17,766 Dependent repositories
4,118,686 Downloads last month

Affected Version Ranges

All affected versions

1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.1.2, 1.1.3

All unaffected versions

1.1.4

robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

References: