All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| rangy(npm) | 0 | N/A | N/A |
CVSS Metrics