Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| loader-utils(npm) | 2.0.0 | 2.0.3 | N/A |
| loader-utils(npm) | 0 | 1.4.1 | N/A |
CVSS Metrics