Loading HuntDB...

GHSA-h466-j336-74wx

GitHub Security Advisory

Prototype Pollution in mpath

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Versions of `mpath` before 0.5.1 are vulnerable to prototype pollution. Provided certain input `mpath` can add or modify properties of the `Object` prototype. These properties will be present on all objects.

## Recommendation

Update to version `0.5.1` or later.

Affected Packages

npm mpath
Affected versions: 0 (fixed in 0.5.1)

Related CVEs

Key Information

GHSA ID
GHSA-h466-j336-74wx
Published
February 7, 2019 6:17 PM
Last Modified
September 7, 2023 6:22 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
mpath
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 2, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.