PT-2022-9026 · Unknown · Hughsk Flat

·

CVE-2020-36632

·

Published

2022-12-25

·

Updated

2026-06-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions hughsk flat versions up to 5.0.0
Description A critical vulnerability was found in hughsk flat, affecting the function unflatten of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes, known as 'prototype pollution'. It is possible to initiate the attack remotely.
Recommendations For versions up to 5.0.0, upgrade to version 5.0.1 to address this issue. As a temporary workaround, consider disabling the unflatten function until a patch is available.

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36632
GHSA-2J2X-2GPW-G8FM

Affected Products

Hughsk Flat