This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing an attacker to add or modify an object's prototype. Note: This vulnerability derives from an incomplete fix in SNYK-JS-NOTEVIL-608878. This package has been deprecated.
{
"cwe_ids": [
"CWE-1321"
],
"nvd_published_at": "2022-03-17T12:15:00Z",
"github_reviewed": true,
"severity": "MODERATE",
"github_reviewed_at": "2022-03-18T23:07:57Z"
}