GHSA-624g-8qjg-8qxf
HIGHCVE-2024-32866Conform allows the parsing of nested objects in the form of object.property. Due to an improper implementation of this feature, an attacker can exploit it to trigger prototype pollution by passing a crafted input to parseWith... functions.
- Affected
- < 0.9.2, >= 1.0.0, <= 1.1.0
- Fixed in
- 0.9.2
- Weakness
- CWE-1321
- Published
- 2024-04-23
- Source
- github