QID 982014
QID 982014: Nodejs (npm) Security Update for think-helper (GHSA-vr5m-3h59-7jcp)
Security update has been released for think-helper to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
The software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
Solution
`[email protected]` patched it, anyone used `think-helper` should upgrade to `>=1.1.3` version.
Vendor References
- GHSA-vr5m-3h59-7jcp -
github.com/advisories/GHSA-vr5m-3h59-7jcp
CVEs related to QID 982014
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vr5m-3h59-7jcp | think-helper |
|