GHSA-jjff-q3q4-5hh8CriticalCVSS 9.8

@andrei-tatar/nora-firebase-common Prototype Pollution vulnerability

Published
April 18, 2024
Last Modified
June 11, 2026

🔗 CVE IDs covered (1)

📋 Description

An issue inandrei-tatar nora-firebase-common between v.1.0.41 and v.1.12.2 allows a remote attacker to execute arbitrary code via a crafted script to the updateState parameter of the updateStateInternal method.

🎯 Affected products1

  • npm/@andrei-tatar/nora-firebase-common:>= 1.0.41, < 1.12.3

🔗 References (5)