@eivifj/dot@1.0.1 vulnerabilities

Get and set object properties with dot notation

Direct Vulnerabilities

Known vulnerabilities in the @eivifj/dot package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Prototype Pollution

@eivifj/dot is a module that gets and sets object properties with dot notation.

Affected versions of this package are vulnerable to Prototype Pollution. The function set could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.

How to fix Prototype Pollution?

Upgrade @eivifj/dot to version 1.0.3 or higher.

<1.0.3