Vulnerabilities > Merge Object Project

DATE CVE VULNERABILITY TITLE RISK
2018-07-03 CVE-2018-3753 Improper Input Validation vulnerability in Merge-Object Project Merge-Object 0.1.0/1.0.0
The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function.
network
low complexity
merge-object-project CWE-20
7.5