diegohaz/bodymen

diegohaz/bodymen

Releases6
Frequency8 months 1 week
Last Release
Stars48
Body parser middleware for MongoDB, Express and Nodejs (MEN)

CVE History

CVEPublishedCVSS v3CVSS v2
6.3 MEDIUM6.5 MEDIUM

bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.