CVE-2023-26102

7.5HIGH

All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify pr

Veröffentlicht: 2/24/2023Aktualisiert: 3/11/2025

Beschreibung

All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype

KI-AnalyseKI-gestützt

Betroffene Produkte

rangy_projectrangy
-

Referenzen