Closed gkmr507 closed 4 years ago
If required I can submit a POC through a secured channel. Thanks.
Yes please, email in my profile.
Never mind, I could reproduce - working on a fix.
Thanks for the quick response and fix. But the issue is still reproducible. Sent a mail with POC(how to reproduce) and opened an issue in HackerOne as well. Ref: https://hackerone.com/reports/980649
Oops sorry about that I went too fast.
Fixed in 1.0.3
Thank you for the report.
Prototype Pollution: This package fails to restrict access to prototypes of objects, allowing for modification of prototype behavior, which may allow obtaining sensitive information/DoS/RCE.
If required I can submit a POC through a secured channel. Thanks.