CVE-2021-23771: Sandbox escape in notevil and argencoders-notevil
(updated )
This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing an attacker to add or modify an object’s prototype. Note: This vulnerability derives from an incomplete fix in SNYK-JS-NOTEVIL-608878.
References
Detect and mitigate CVE-2021-23771 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →