conductor-oss / conductor-oss/javascript-sdk
[GHSA-mh29-5h37-fv8m] js-yaml@3.14.1: Prototype pollution in merge
Open
security
vulnerability
- Dominant language
- TypeScript
- Stars
- 58
- Forks
- 20
- Avg merge
- 1d 13h
- Merged PRs (30d)
- 7
Description
## Vulnerability Report
| CVE | Library | Installed | Fixed |
|-----|---------|-----------|-------|
| GHSA-mh29-5h37-fv8m | js-yaml | 3.14.1 | 3.14.2 |
### Summary
js-yaml has prototype pollution in merge (<<).
### References
- [GHSA-mh29-5h37-fv8m](https://osv.dev/vulnerability/GHSA-mh29-5h37-fv8m)
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.