[GHSA-p2ph-7g93-hw3m] Vue I18n Allows Prototype Pollution in handleFlatJson#8177
[GHSA-p2ph-7g93-hw3m] Vue I18n Allows Prototype Pollution in handleFlatJson#8177G-Rath wants to merge 1 commit into
handleFlatJson#8177Conversation
|
Hi there @kazupon! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
There was a problem hiding this comment.
Pull request overview
This pull request updates the OSV advisory entry for GHSA-p2ph-7g93-hw3m (Vue I18n prototype pollution in handleFlatJson) to reflect corrected metadata and impact information.
Changes:
- Updated the advisory’s
modifiedtimestamp to reflect the latest upstream modification time. - Adjusted the CVSS v4 vector string and raised
database_specific.severitytoCRITICAL. - Corrected the affected version range for
@intlify/vue-i18n-core(10.x line) so the fix is recorded as10.0.6and removed the now-redundantlast_known_affected_version_rangefield for that range.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Updates
Comments
patch version was incorrect, and apparently the severity string was too (according to the form 🤷)