GHSA-xp9c-82x8-7f67
HIGHCVE-2021-21297Node-RED 1.2.7 and earlier contains a Prototype Pollution vulnerability in the admin API. A badly formed request can modify the prototype of the default JavaScript Object with the potential to affect the default behaviour of the Node-RED runtime.
- Affected
- < 1.2.8
- Fixed in
- 1.2.8
- Weakness
- CWE-915
- Published
- 2021-02-26
- Source
- github