A prototype pollution in the lib.merge function of cli...
High severity
Unreviewed
Published
Feb 6, 2025
to the GitHub Advisory Database
•
Updated Feb 6, 2025
Description
Published by the National Vulnerability Database
Feb 5, 2025
Published to the GitHub Advisory Database
Feb 6, 2025
Last updated
Feb 6, 2025
A prototype pollution in the lib.merge function of cli-util v1.1.27 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
References