GHSA-qxc2-j82w-r537
Faker: helpers.fake exploitable into arbritary code execution
Quick fix
GHSA-qxc2-j82w-r537 — @faker-js/faker: upgrade to the fixed version with the command below.
npm install @faker-js/faker@10.5.0Details
### Summary
`faker.helpers.fake` can be tricked into arbritary code execution.
### Details
fakeEval.resolveProperty resolves properties on functions itself instead of resolving the nested function first. This can be addressed by recursively calling resolveProperty instead of accessing the property after one iteration.
### PoC
Go to https://fakerjs.dev/ Open Browser console and run
````ts await enableFaker(); // or import faker faker.rawDefinitions.test = (() => () => {}); // Any function that returns a function faker.helpers.fake(`{{test.constructor(alert('PowerLevel: Eval'))}}`); ````
### Impact
The Fake method claims:
> It is also NOT possible to use any non-faker methods or plain javascript in such patterns.
Which is objectively false, since any global gets fully accessible in the fake string.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/faker-js/faker/security/advisories/GHSA-qxc2-j82w-r537[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-73231[ADVISORY]
- https://github.com/faker-js/faker/pull/3852[WEB]
- https://github.com/faker-js/faker/commit/54586208f904012f57c50b46cc1ad32bcbe4bfb7[WEB]
- https://github.com/faker-js/faker[PACKAGE]
- https://github.com/faker-js/faker/releases/tag/v10.5.0[WEB]