VDB
Sign up
MEDIUM5.5

GHSA-4hwx-xcc5-2hfc

tarteaucitron.js allows prototype pollution via custom text injection

Quick fix

GHSA-4hwx-xcc5-2hfc — tarteaucitronjs: upgrade to the fixed version with the command below.

npm install tarteaucitronjs@1.20.1

Details

A vulnerability was identified in `tarteaucitron.js`, where the `addOrUpdate` function, used for applying custom texts, did not properly validate input. This allowed an attacker with direct access to the site's source code or a CMS plugin to manipulate JavaScript object prototypes, leading to potential security risks such as data corruption or unintended code execution.

## Impact An attacker with high privileges could exploit this vulnerability to: - Modify object prototypes, affecting core JavaScript behavior, - Cause application crashes or unexpected behavior, - Potentially introduce further security vulnerabilities depending on the application's architecture.

## Fix https://github.com/AmauriC/tarteaucitron.js/commit/74c354c413ee3f82dff97a15a0a43942887c2b5b The issue was resolved by ensuring that user-controlled inputs cannot modify JavaScript object prototypes.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/tarteaucitronjs
Introduced in: 0Fixed in: 1.20.1
Fixnpm install tarteaucitronjs@1.20.1

References