OsVault/npm/flat
npm4 critical

flat

21 known vulnerabilities · 4 critical · 1 high

CVE-2020-36632MEDIUM

flat vulnerable to Prototype Pollution

Published Dec 25, 2022
CVE-2023-26135HIGH

flatnest Prototype Pollution vulnerability

Published Jun 30, 2023
GHSA-mwv9-gp5h-frr4

Sveltejs devalue's `devalue.parse` and `devalue.unflatten` emit objects with `__proto__` own properties

Published Mar 12, 2026
CVE-2026-1526

Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression

Published Mar 13, 2026
MAL-2022-4660

Malicious code in model-flattening (npm)

Published Jun 20, 2022
CVE-2021-25927CRITICAL

Prototype pollution in safe-flat

Published Jun 21, 2021
CVE-2026-30226

devalue has prototype pollution in devalue.parse and devalue.unflatten

Published Mar 12, 2026
MAL-2022-1522

Malicious code in bfx-facs-deflate (npm)

Published Jun 20, 2022
CVE-2024-38988CRITICAL

@alizeait/unflatto Prototype Pollution

Published Apr 1, 2025
CVE-2020-7713CRITICAL

Prototype Pollution in arr-flatten-unflatten

Published May 6, 2021
CVE-2020-28279CRITICAL

flattenizer vulnerable to prototype pollution

Published May 24, 2022
MAL-2022-3070

Malicious code in flat-surface-shader (npm)

Published Jun 20, 2022
CVE-2019-10794MEDIUM

component-flatten vulnerable to Prototype Pollution

Published May 24, 2022
MAL-2022-7326

Malicious code in yarn-design-system-flatpickr (npm)

Published Jun 20, 2022
CVE-2026-33228

Prototype Pollution via parse() in NodeJS flatted

Published Mar 19, 2026
MAL-2025-2464

Malicious code in eslint8_flat_config_mjs (npm)

Published Mar 17, 2025
CVE-2026-27601

Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack

Published Mar 3, 2026
GHSA-vrqm-gvq7-rrwh

PDFME Affected by Decompression Bomb in FlateDecode Stream Parsing Causes Memory Exhaustion DoS

Published Mar 20, 2026
MAL-2025-1552

Malicious code in flow-inflation-client (npm)

Published Feb 23, 2025
MAL-2025-191095

Malicious code in flatten-unflatten (npm)

Published Nov 24, 2025
CVE-2026-32141

flatted vulnerable to unbounded recursion DoS in parse() revive phase

Published Mar 13, 2026
Check your entire dependency tree at onceRun dependency scan →