web3-core-subscriptions@1.10.0 vulnerabilities

Manages web3 subscriptions. This is an internal package.

Direct Vulnerabilities

Known vulnerabilities in the web3-core-subscriptions package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Prototype Pollution

Affected versions of this package are vulnerable to Prototype Pollution via the attachToObject function. An attacker can inject arbitrary properties into Object.prototype by supplying a crafted payload, potentially leading to application instability or service disruption.

How to fix Prototype Pollution?

There is no fixed version for web3-core-subscriptions.

*