VDB
Sign up
MEDIUM5.6

GHSA-vh95-rmgr-6w4m

Prototype Pollution in minimist

Quick fix

GHSA-vh95-rmgr-6w4m — minimist: upgrade to the fixed version with the command below.

npm install minimist@0.2.1

Details

Affected versions of `minimist` are vulnerable to prototype pollution. Arguments are not properly sanitized, allowing an attacker to modify the prototype of `Object`, causing the addition or modification of an existing property that will exist on all objects. Parsing the argument `--__proto__.y=Polluted` adds a `y` property with value `Polluted` to all objects. The argument `--__proto__=Polluted` raises and uncaught error and crashes the application. This is exploitable if attackers have control over the arguments being passed to `minimist`.

## Recommendation

Upgrade to versions 0.2.1, 1.2.3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/minimist
Introduced in: 0Fixed in: 0.2.1
Fixnpm install minimist@0.2.1
npm/minimist
Introduced in: 1.0.0Fixed in: 1.2.3
Fixnpm install minimist@1.2.3

References