remy/undefsafe

remy/undefsafe

Releases12
Frequency8 months 2 weeks
Last Release
Stars72
Simple *function* for retrieving deep object properties without getting "Cannot read property 'X' of undefined"

CVE History

CVEPublishedCVSS v3CVSS v2
6.3 MEDIUM6.5 MEDIUM

undefsafe before 2.0.3 is vulnerable to Prototype Pollution. The 'a' function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.