2.1.39
8 years ago
1 months ago
Known vulnerabilities in the keyd package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
keyd is an a small library for using and manipulating key paths in JavaScript. Affected versions of this package are vulnerable to Prototype Pollution. It allows an attacker to inject properties on Object.prototype. How to fix Prototype Pollution? Upgrade | <1.4.3 |