VDB
Sign up
MEDIUM5.9

GHSA-529q-4j3p-7c5r

algoliasearch-helper is vulnerable to Prototype Pollution in _merge()

Quick fix

GHSA-529q-4j3p-7c5r — algoliasearch-helper: upgrade to the fixed version with the command below.

npm install algoliasearch-helper@3.11.2

Details

Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype to be written even though doing so throws an error. In the "extreme edge-case" that the resulting error is caught, code injected into the user-supplied search parameter may be exeucted.

This is related to but distinct from the issue reported in [CVE-2021-23433](https://security.snyk.io/vuln/SNYK-JS-ALGOLIASEARCHHELPER-1570421).

**NOTE:** This vulnerability is not exploitable in the default configuration of InstantSearch since searchParameters are not modifiable by users.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/algoliasearch-helper
Introduced in: 2.0.0-rc1Fixed in: 3.11.2
Fixnpm install algoliasearch-helper@3.11.2

References