GHSA-34q8-jcq6-mc37
GitHub Security Advisory
uPlot Prototype Pollution vulnerability
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.
Affected Packages
npm
uplot
Affected versions:
0
(fixed in 1.6.31)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: June 15, 2025 6:24 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.