alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
The problem has been patched in 1.0.3
https://github.com/advisories/GHSA-799q-f2px-wx8c
{ "nvd_published_at": null, "cwe_ids": [ "CWE-1321" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2025-04-01T14:54:36Z" }