VDB
Sign up
CRITICAL9.8

GHSA-v9p9-535w-4285

Prototype Pollution in litespeed.js and appwrite/server-ce

Quick fix

GHSA-v9p9-535w-4285 — litespeed.js: upgrade to the fixed version with the command below.

npm install litespeed.js@0.3.12

Details

This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not properly sanitized leading to a Prototype Pollution vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/litespeed.js
Introduced in: 0Fixed in: 0.3.12
Fixnpm install litespeed.js@0.3.12
Packagist/appwrite/server-ce
Introduced in: 0.12.0Fixed in: 0.12.2
Fixcomposer require appwrite/server-ce:^0.12.2
Packagist/appwrite/server-ce
Introduced in: 0Fixed in: 0.11.1
Fixcomposer require appwrite/server-ce:^0.11.1

References