expand-object@0.3.2 vulnerabilities

Expand a string into a JavaScript object using a simple notation. Use the CLI or as a node.js lib.

Direct Vulnerabilities

Known vulnerabilities in the expand-object package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Prototype Pollution

expand-object is an Expand a string into a JavaScript object using a simple notation. Use the CLI or as a node.js lib.

Affected versions of this package are vulnerable to Prototype Pollution in the expand() function in index.js. This function expands the given string into an object and allows a nested property to be set without checking the provided keys for sensitive properties like __proto__.

How to fix Prototype Pollution?

There is no fixed version for expand-object.

>=0.0.0