hoolock@2.2.0 vulnerabilities

Suite of 43 lightweight utilities designed to maintain a small footprint when bundled, without compromising on ease of integration and use.

Direct Vulnerabilities

Known vulnerabilities in the hoolock package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Prototype Pollution

hoolock is a Suite of 43 lightweight utilities designed to maintain a small footprint when bundled, without compromising on ease of integration and use.

Affected versions of this package are vulnerable to Prototype Pollution via the utility functions get, set, and update. An attacker can manipulate the prototype of an object, potentially leading to the alteration of behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions.

How to fix Prototype Pollution?

Upgrade hoolock to version 2.2.1 or higher.

>=2.0.0 <2.2.1