Advisories for Npm/@Alizeait/Unflatto package

2025

Duplicate Advisory: @alizeait/unflatto Prototype Pollution via `exports.unflatto` Method

Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-q8jq-4rm5-4hm5. This link is maintained to preserve external references. Original Description alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.