VDB
Sign up
CRITICAL9.9

GHSA-9v98-6g37-x9g6

deepstream is vulnerable to prototype pollution

Quick fix

GHSA-9v98-6g37-x9g6 — @deepstream/server: upgrade to the fixed version with the command below.

npm install @deepstream/server@10.0.5

Details

### Impact Prototype pollution in deepstream server v <=10.0.4. Potential privilege escalation from any authenticated user with write permission to any record.

### Patches Yes, upgrade to v10.0.5

### Workarounds Filter out all messages containing the path `__proto__`, `constructor`, `prototype`, **before they reach the server's message pipeline**

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@deepstream/server
Introduced in: 0Fixed in: 10.0.5
Fixnpm install @deepstream/server@10.0.5

References