CRITICAL9.8
GHSA-8v3j-jfg3-v3fv
Prototype Pollution in Sails.js
Details
Sails.js <= 1.5.2 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadActionModules(). A [patch](https://github.com/balderdashy/sails/commit/7c5379a656bb305c958df1dcc2b51a9668830358) is available in the `master` branch of Sails.js's GItHub repository.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/sails
Introduced in:
0No fixed version published yet for sails (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-44908[ADVISORY]
- https://github.com/balderdashy/sails/issues/7209[WEB]
- https://github.com/balderdashy/sails/commit/7c5379a656bb305c958df1dcc2b51a9668830358[WEB]
- https://github.com/Marynk/JavaScript-vulnerability-detection/blob/main/sailsJS%20PoC.zip[WEB]
- https://github.com/balderdashy/sails[PACKAGE]
- https://github.com/balderdashy/sails/blob/master/lib/app/private/controller/load-action-modules.js#L32[WEB]