Geta/NestedObjectAssign

Geta/NestedObjectAssign

CVE History

CVEPublishedCVSS v2CVSS v3
CVE-2021-233297.5 HIGH5 MEDIUM
The package nested-object-assign before 1.0.4 are vulnerable to Prototype Pollution via the default function, as demonstrated by running the PoC below.