Headline
GHSA-4c2g-hx49-7h25: Prototype pollution not blocked by object-path related utilities in hoolock
Impact
Utility functions related to object paths (get, set and update) did not block attempts to access or alter object prototypes.
Patches
The get, set and update functions will throw a TypeError when a user attempts to access or alter inherited properties in versions >=2.2.1.
Prototype pollution not blocked by object-path related utilities in hoolock
Moderate severity GitHub Reviewed Published Jan 21, 2024 in elijahharry/hoolock • Updated Jan 23, 2024