csvtojson@2.0.2 vulnerabilities

A tool concentrating on converting csv data to JSON with customised parser supporting

  • latest version

    2.0.14

  • latest non vulnerable version

  • first published

    12 years ago

  • latest version published

    1 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the csvtojson package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Prototype Pollution

    csvtojson is an A tool concentrating on converting csv data to JSON with customised parser supporting

    Affected versions of this package are vulnerable to Prototype Pollution in the parser_jsonarray process due to insufficient sanitization of nested header names. An attacker can cause denial of service or unexpected application behavior by supplying specially crafted CSV input containing malicious header fields that manipulate prototype chains.

    How to fix Prototype Pollution?

    Upgrade csvtojson to version 2.0.13 or higher.

    <2.0.13