GHSA-c8xx-jpr5-7m25MediumCVSS 4.0

Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the...

Published
July 21, 2026
Last Modified
July 21, 2026

🔗 CVE IDs covered (1)

📋 Description

Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a crafted property path containing special keys such as proto.

🔗 References (6)