web3-utils@1.0.0-beta.48 vulnerabilities

Collection of utility functions used in web3.js.

Direct Vulnerabilities

Known vulnerabilities in the web3-utils package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Prototype Pollution

web3-utils is a Collection of utility functions used in web3.js.

Affected versions of this package are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions.

How to fix Prototype Pollution?

Upgrade web3-utils to version 4.2.1 or higher.

<4.2.1