Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Depath 安全漏洞
Vulnerability Description
Depath是Janry个人开发者的一个对象/数组的路径匹配器/获取器/设置器。 Depath v1.0.6版本存在安全漏洞,该漏洞源于原型污染,可能导致任意代码执行或拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A