CRITICAL 9.8 Packagist
plotly.js prototype pollution vulnerability
GHSA-wjc4-73q6-gv3m · CVE-2023-46308
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
In Plotly plotly.js before 2.25.2, plot API calls have a risk of proto being polluted in expandObjectPaths or nestedProperty.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-46308
- WEB https://github.com/plotly/plotly.R/issues/2463
- WEB https://github.com/plotly/plotly.js/commit/02498404c8ad7a3395191e65694fb142a37b0fe9
- WEB https://github.com/plotly/plotly.js/commit/5efd2a1f07a418b230a5626fc6c1c7929c47949d
- PACKAGE https://github.com/plotly/plotly.js
- WEB https://github.com/plotly/plotly.js/releases/tag/v2.25.2
- WEB https://plotly.com/javascript
Ready to move
Start Securing
Free, no credit card | First findings in minutes