cool-path
v1.1.2npm· JavaScriptPath Matcher/Getter/Setter for Object/Array
The verdict
Has 1 high-severity advisory. Verify a patched version exists before using. Check the OSV link for the fixed-in version.
Check the OSV link for the fixed-in version.
Live from the npm registry · derived rules, not AI
How it scores
MaintenanceAbandoned
PopularityUnknown
Security1 advisory
LicensePermissive
DepsZero deps
Maintenance
Last published 5 years ago.
Popularity
Download count unavailable.
Security
1 known advisory (worst: high severity).
License
MIT
Dependencies
No runtime dependencies
Security advisories
Live from OSV.dev · cached 24h- HIGHdepath and cool-path vulnerable to Prototype Pollution via `set()` MethodGHSA-4h4x-4m75-47j4 Published 2025-03-28
Recent releases
- 1.1.25 years ago
- 1.1.15 years ago
- 1.1.05 years ago
- 1.0.115 years ago
- 1.0.105 years ago
- 1.0.95 years ago
- 1.0.85 years ago
- 1.0.75 years ago