VDB
KO
CRITICAL 9.8

GHSA-h755-8qp9-cq85

protobufjs Prototype Pollution vulnerability

Details

protobuf.js (aka protobufjs) 6.10.0 until 6.11.4 and 7.0.0 until 7.2.4 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by adding and overwriting its data and functions. Exploitation can involve: (1) using the function parse to parse protobuf messages on the fly, (2) loading .proto files by using load/loadSync functions, or (3) providing untrusted input to the functions ReflectionObject.setParsedOption and util.setProperty. NOTE: this CVE Record is about `Object.constructor.prototype.<new-property> = ...;` whereas CVE-2022-25878 was about `Object.__proto__.<new-property> = ...;` instead.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / protobufjs
Introduced in: 7.0.0 Fixed in: 7.2.5
Fix npm install protobufjs@7.2.5
npm / protobufjs
Introduced in: 6.10.0 Fixed in: 6.11.4
Fix npm install protobufjs@6.11.4

References