robinvdvleuten / vuex-persistedstate

💾 Persist and rehydrate your Vuex state between page reloads.
https://npm.im/vuex-persistedstate
MIT License
5.76k stars 375 forks source link

High Severity: Prototype Pollution vulnerability in module shvl #422

Closed prasunk96 closed 3 years ago

prasunk96 commented 3 years ago

Problem description: Snyk had reported High Severity: Prototype Pollution for all the shvl versions released before shvl@2.0.3. The vuex-persistedstate project depends on shvl and therefore became listed as a vulnerable primary dependency in our production project which uses vuex-persistedstate@2.5.4, vue@2.6.10 and vuex@3.1.0. please check below: https://snyk.io/vuln/npm:shvl

Suggested solution: The recommended version of shvl that has the fix for High Severity: Prototype Pollution is shvl@2.0.3 https://snyk.io/test/npm/shvl/2.0.3