GHSA-4hwx-xcc5-2hfc
tarteaucitron.js allows prototype pollution via custom text injection
Quick fix
GHSA-4hwx-xcc5-2hfc — tarteaucitronjs: upgrade to the fixed version with the command below.
npm install tarteaucitronjs@1.20.1Details
A vulnerability was identified in `tarteaucitron.js`, where the `addOrUpdate` function, used for applying custom texts, did not properly validate input. This allowed an attacker with direct access to the site's source code or a CMS plugin to manipulate JavaScript object prototypes, leading to potential security risks such as data corruption or unintended code execution.
## Impact An attacker with high privileges could exploit this vulnerability to: - Modify object prototypes, affecting core JavaScript behavior, - Cause application crashes or unexpected behavior, - Potentially introduce further security vulnerabilities depending on the application's architecture.
## Fix https://github.com/AmauriC/tarteaucitron.js/commit/74c354c413ee3f82dff97a15a0a43942887c2b5b The issue was resolved by ensuring that user-controlled inputs cannot modify JavaScript object prototypes.
Are you affected?
Enter the version of the package you're using.