sonnyp / JSON8

JSON toolkit for JavaScript.
ISC License
104 stars 13 forks source link

find Prototype pollution in add.js #153

Open lelecolacola123 opened 1 year ago

lelecolacola123 commented 1 year ago

Prototype pollution vulnerability in function add() in json8-patch/lib/add.js in json8-patch1.0.6 via the function add and variable add The function usevariable partent and function add lead to Prototype pollution in line 43