Headline
GHSA-4hq8-jgr8-mw9j: grunt-util-property 0.0.2 function call can add/modify properties of Object.prototype using a __proto__ payload
This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype
using a __proto__
payload.
grunt-util-property 0.0.2 function call can add/modify properties of Object.prototype using a __proto__ payload
Moderate severity GitHub Reviewed Published Jul 18, 2022 • Updated Jul 21, 2022
Related news
CVE-2020-7641
This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.