VendorsKind-of Projectkind-of6.0.2
Vulnerabilities

Kind-of Project Kind-of 6.0.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2019-20149
ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.
Published 2019-12-30 · Modified
7.5EPSS 0.023