Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade nunjucks
to version 3.2.3 or higher.
nunjucks is a powerful templating engine with inheritance, asynchronous control, and more (jinja2 inspired).
Affected versions of this package are vulnerable to Prototype Pollution.
via the constructor
class in nunjucks/src/runtime.js.