sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of the 'Object.prototype' by abusing the 'set' function located in 'js/set.js'.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| sds(npm) | 0 | 4.0.0 | N/A |
CVSS Metrics