Advisories for Npm/Radashi package

2025

radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

This is a prototype pollution vulnerability. It impacts users of the set function within the Radashi library. If an attacker can control parts of the path argument to the set function, they could potentially modify the prototype of all objects in the JavaScript runtime, leading to unexpected behavior, denial of service, or even remote code execution in some specific scenarios.