All vulnerabilities
CVE-2020-36604
hoek subject to prototype pollution via the clone function.
Description
hoek versions prior to 8.5.1, and 9.x prior to 9.0.3 are vulnerable to prototype pollution in the clone function. If an object with the proto key is passed to clone() the key is converted to a prototype. This issue has been patched in version 9.0.3, and backported to 8.5.1.
Patch Available
Fix available through Seal Security.
No upgrade required, protect your application instantly.
Fix without upgrading
Score
Severity
Ecosystem
JavaScript
Publish Date
September 24, 2022
Modified Date
May 28, 2025
Score Vector
Affected Versions

