jaredhanson / jaredhanson/utils-merge

🚨 Potential Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)

Open
#8 5 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
69
Forks
19
PR merge metrics
No merged PRs in 30d

Description

👋 Hello, @jaredhanson - a potential high severity Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321) vulnerability in your repository has been disclosed to us.

#### Next Steps

1️⃣ Visit **https://huntr.dev/bounties/1-other-jaredhanson/utils-merge** for more advisory information.

2️⃣ **[Sign-up](https://huntr.dev/)** to validate or speak to the researcher for more assistance.

3️⃣ Propose a patch or outsource it to our community - whoever fixes it gets paid.

---

#### Confused or need more help?

- Join us on our **[Discord](https://huntr.dev/discord)** and a member of our team will be happy to help! 🤗

- Speak to a member of our team: @JamieSlome

---

*This issue was automatically generated by [huntr.dev](https://huntr.dev) - a bug bounty board for securing open source code.*

Contributor guide

Open the contributing guide

Research direction

Start with the linked Huntr advisory for the vulnerability details and affected behavior, then inspect the merge() utility entry point in this repository. Use the advisory's reproduction or validation guidance to determine when the prototype-pollution issue is resolved.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.