GHSA-h466-j336-74wx
GitHub Security Advisory
Prototype Pollution in mpath
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Versions of `mpath` before 0.5.1 are vulnerable to prototype pollution. Provided certain input `mpath` can add or modify properties of the `Object` prototype. These properties will be present on all objects.
## Recommendation
Update to version `0.5.1` or later.
Affected Packages
npm
mpath
Affected versions:
0
(fixed in 0.5.1)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 2, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.