{"id":"GHSA-c3px-v9c7-m734","aliases":[],"url":"https://o3.security/vulnerability/GHSA-c3px-v9c7-m734","summary":"Prototype Pollution in mithril","details":"Affected versions of `mithril`are vulnerable to prototype pollution. The function `parseQueryString` may allow a malicious user to modify the prototype of `Object`, causing the addition or modification of an existing property that will exist on all objects. A payload such as `__proto__%5BtoString%5D=123` in the query string would change the `toString()` function to `123`.\n\n\n\n## Recommendation\n\nIf you are using mithril 2.x, upgrade to version 2.0.2 or later.\nIf you are using mithril 1.x, upgrade to version 1.1.7 or later.","published":"2020-09-03T19:04:39Z","modified":"2020-08-31T18:47:02Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"mithril","fixedVersion":"1.1.7"},{"ecosystem":"npm","name":"mithril","fixedVersion":"2.0.2"}],"fix":null,"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1094"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T18:47:02Z"}}