GHSA-r8c2-2qwq-94p6
rollbar vulnerable to prototype pollution
Quick fix
GHSA-r8c2-2qwq-94p6 — rollbar: upgrade to the fixed version with the command below.
npm install rollbar@2.26.5Details
### Impact
Prototype pollution potential with the utility function `rollbar/src/utility`.`set()`. No impact when using the published public interface.
If application code directly imports `set` from `rollbar/src/utility` and then calls `set` with untrusted input in the second argument, it is vulnerable to prototype pollution.
POC:
```js const obj = {}; require("rollbar/src/utility").set(obj, "__proto__.polluted", "vulnerable"); console.log({}.polluted !== undefined ? '[POLLUTION_TRIGGERED]':''); ```
### Patches
Fixed in version 2.26.5 and 3.0.0-beta5.
### Workarounds
If application code directly imports `set` from `rollbar/src/utility`, ensure that the second argument does not receive untrusted input.
### References
https://github.com/rollbar/rollbar.js/issues/1333#issuecomment-3353720946
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/rollbar/rollbar.js/security/advisories/GHSA-r8c2-2qwq-94p6[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-57325[ADVISORY]
- https://github.com/rollbar/rollbar.js/issues/1333[WEB]
- https://github.com/rollbar/rollbar.js/commit/d717def8b68f4a947975d0aebb729869cdb2d343[WEB]
- https://github.com/VulnSageAgent/PoCs/blob/main/JavaScript/prototype-pollution/rollbar%402.26.4/index.js[WEB]
- https://github.com/VulnSageAgent/PoCs/tree/main/JavaScript/prototype-pollution/CVE-2025-57325[WEB]
- https://github.com/rollbar/rollbar.js[PACKAGE]