The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
| Software | From | Fixed in |
|---|---|---|
| digitalbazaar / forge | - | 0.10.0 |
digitalbazaar / node-forge
|
- | 0.10.0 |