Skip to content

fix: upgrade to copy-anything 4#317

Merged
Skn0tt merged 1 commit into
flightcontrolhq:mainfrom
jacquesg:fix/copy-anything
Aug 6, 2025
Merged

fix: upgrade to copy-anything 4#317
Skn0tt merged 1 commit into
flightcontrolhq:mainfrom
jacquesg:fix/copy-anything

Conversation

@jacquesg

Copy link
Copy Markdown
Contributor

copy-anything:

"Affected versions of this package are vulnerable to prototype pollution, allowing an attacker to inject properties such as isAdmin into an object's prototype when copying an object containing a __proto__ property using the copy function of the copy-anything library. This can lead to unauthorized access, privilege escalation, and unpredictable application behavior due to bypassed permission checks."

See: mesqueeb/copy-anything#11

@jacquesg jacquesg requested a review from Skn0tt as a code owner April 11, 2025 12:21
@Skn0tt Skn0tt merged commit 6dc63da into flightcontrolhq:main Aug 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants