-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the extend function's handling of the 'unflat' option. The commit diff shows critical security checks were added to extendOneKV (called by extendOne) to block 'proto' keys and prevent prototype modification. Before the fix, the code would process user-controlled keys without sanitization, allowing prototype pollution via specially crafted property paths. The affected functions are clearly identified in the patched files with security-related changes in their property handling logic.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| tree-kit | npm | < 0.7.5 | 0.7.5 |
Ongoing coverage of React2Shell