stealjs / steal

Gets JavaScript
https://stealjs.com
MIT License
1.37k stars 521 forks source link

[CVE-2022-37265]/ Prototype pollution found in babel.js #1534

Open secdevlpr26 opened 1 year ago

secdevlpr26 commented 1 year ago

Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.

The prototype pollution vulnerability can be mitigated with several best practices described here: https://learn.snyk.io/lessons/prototype-pollution/javascript/