GHSA-3c9c-2p65-qvwv
Prototype pollution in aurelia-path
Quick fix
GHSA-3c9c-2p65-qvwv — aurelia-path: upgrade to the fixed version with the command below.
npm install aurelia-path@1.1.7Details
### Impact The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The majority of this will be Aurelia applications that employ the `aurelia-router` package. An example is this could allow an attacker to change the prototype of base object class `Object` by tricking an application to parse the following URL: `https://aurelia.io/blog/?__proto__[asdf]=asdf`
### Patches The problem should be patched in version `1.1.7`. Any version earlier than this is vulnerable.
### Workarounds A partial work around is to free the Object prototype: ```ts Object.freeze(Object.prototype) ```
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/aurelia/path/security/advisories/GHSA-3c9c-2p65-qvwv[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-41097[ADVISORY]
- https://github.com/aurelia/path/issues/44[WEB]
- https://github.com/aurelia/path/commit/7c4e235433a4a2df9acc313fbe891758084fdec1[WEB]
- https://github.com/aurelia/path[PACKAGE]
- https://github.com/aurelia/path/releases/tag/1.1.7[WEB]
- https://www.npmjs.com/package/aurelia-path[WEB]