Exposure of Resource to Wrong Sphere in Kind-of - CVE-2019-20149
Published: August 2, 2023
Kind-of
jonschlinkert
Description
The vulnerability allows a remote attacker to modify files on the system.
The vulnerability exists due to ctorName in index.js in kind-of allows external user input to overwrite certain internal attributes via a conflicting name. A remote unauthenticated attacker can send a specially crafted payload to overwrite builtin attribute and manipulate the type detection result.