Skip to content

@alizeait/unflatto Prototype Pollution

High
alizeait published GHSA-q8jq-4rm5-4hm5 Apr 1, 2025

Package

npm @alizeait/unflatto (npm)

Affected versions

1.0.2

Patched versions

1.0.3

Description

Impact

alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

Patches

The problem has been patched in 1.0.3

References

GHSA-799q-f2px-wx8c

Severity

High

CVE ID

CVE-2024-38988

Weaknesses

No CWEs