Headline
GHSA-4c2g-hx49-7h25: Prototype pollution not blocked by object-path related utilities in hoolock
Impact
Utility functions related to object paths (get
, set
and update
) did not block attempts to access or alter object prototypes.
Patches
The get
, set
and update
functions will throw a TypeError
when a user attempts to access or alter inherited properties in versions >=2.2.1.
Prototype pollution not blocked by object-path related utilities in hoolock
Moderate severity GitHub Reviewed Published Jan 21, 2024 in elijahharry/hoolock • Updated Jan 23, 2024