lowVulnerability

GHSA-8qm3-746x-r74r

Under certain circumstances, `uneval`ing untrusted data can produce output code that will create objects with polluted prototypes when later `eval`ed, meaning the output data can be a different shape from the input data.

Properties

ghsa_id
GHSA-8qm3-746x-r74r
severity
low
summary
devalue `uneval`ed code can create objects with polluted prototypes when `eval`ed
cve_id
GHSA-8qm3-746x-r74r
is_ghsa_only
true
ghsa_published
2026-02-19T20:29:17Z
source_url
https://github.com/advisories/GHSA-8qm3-746x-r74r
ghsa_updated
2026-02-19T20:29:19Z

Related Entities (3)

AFFECTS (1)

[Software]npm/devalue

HAS_WEAKNESS (1)

[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph