VDB
Sign up
CRITICAL9.1

GHSA-3c9c-2p65-qvwv

Prototype pollution in aurelia-path

Quick fix

GHSA-3c9c-2p65-qvwv — aurelia-path: upgrade to the fixed version with the command below.

npm install aurelia-path@1.1.7

Details

### Impact The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The majority of this will be Aurelia applications that employ the `aurelia-router` package. An example is this could allow an attacker to change the prototype of base object class `Object` by tricking an application to parse the following URL: `https://aurelia.io/blog/?__proto__[asdf]=asdf`

### Patches The problem should be patched in version `1.1.7`. Any version earlier than this is vulnerable.

### Workarounds A partial work around is to free the Object prototype: ```ts Object.freeze(Object.prototype) ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/aurelia-path
Introduced in: 0Fixed in: 1.1.7
Fixnpm install aurelia-path@1.1.7

References