Geta/NestedObjectAssign

Geta/NestedObjectAssign

Releases5
Frequency10 months 2 weeks
Last Release
Stars7

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

The package nested-object-assign before 1.0.4 are vulnerable to Prototype Pollution via the default function, as demonstrated by running the PoC below.