GHSA-675m-85rw-j3w4
GitHub Security Advisory
Prototype Pollution in just-extend
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
Versions of `just-extend` before 4.0.0 are vulnerable to prototype pollution. Provided certain input `just-extend` can add or modify properties of the `Object` prototype. These properties will be present on all objects.
## Recommendation
Update to version `4.0.0` or later.
Affected Packages
npm
just-extend
Affected versions:
0
(fixed in 4.0.0)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: August 30, 2025 6:32 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.