MEDIUM
GHSA-8cw4-87c7-c6xx
node-csv: Prototype replacement still reachable via columns path
Quick fix
GHSA-8cw4-87c7-c6xx — csv-parse: upgrade to the fixed version with the command below.
npm install csv-parse@7.0.2Details
### Impact With columns: true and group_columns_by_name: true, a duplicated __proto__ header causes the duplicate-column branch to assign an array to obj['__proto__'], invoking the __proto__ setter and replacing the parsed record object's prototype with attacker-controlled data. Fixed in 7.0.2 (Object.hasOwn duplicate check + Object.defineProperty assignment).
### Patches The problem been patched.
### Workarounds Disable usage of both the columns and group_columns_by_name options.
### References issue #496, PR #497
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/adaltas/node-csv/security/advisories/GHSA-8cw4-87c7-c6xx[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-85063[ADVISORY]
- https://github.com/adaltas/node-csv/issues/496[WEB]
- https://github.com/adaltas/node-csv/pull/497[WEB]
- https://github.com/adaltas/node-csv/commit/eb4d1484589c976dcb977db8dd0b90e015a6f66e[WEB]
- https://github.com/adaltas/node-csv[PACKAGE]