jquense/expr

jquense/expr

Releases6
Frequency4 months 3 weeks
Last Release
Stars26
tiny util for getting and setting deep object props safely

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.