robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep
. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
GSA_kwCzR0hTQS0zcTU2LTljYzItNDZqNM4AA9bz
robinweser fast-loops vulnerable to prototype pollution
Affected Packages | Affected Versions | Fixed Versions | |
---|---|---|---|
npm:fast-loops | < 1.1.4 | 1.1.4 | |
Affected Version RangesAll affected versions1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.1.2, 1.1.3 All unaffected versions1.1.4 |