VDB
Sign up
CRITICAL9.8

GHSA-33f9-j839-rf8h

Prototype Pollution in immer

Quick fix

GHSA-33f9-j839-rf8h — immer: upgrade to the fixed version with the command below.

npm install immer@9.0.6

Details

This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the path parameter are arrays. In particular, this bypass is possible because the condition `(p === "__proto__" || p === "constructor")` in `applyPatches_` returns false if `p` is `['__proto__']` (or `['constructor']`). The `===` operator (strict equality operator) returns false if the operands have different type.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/immer
Introduced in: 7.0.0Fixed in: 9.0.6
Fixnpm install immer@9.0.6

References