timdown/rangy

timdown/rangy

Releases26
Frequency6 months 3 weeks
Last Release
Stars2.3K
A cross-browser JavaScript range and selection library.

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype