CRITICAL9.8
GHSA-x9vf-53q3-cvx6
CASL Ability is Vulnerable to Prototype Pollution
Quick fix
GHSA-x9vf-53q3-cvx6 — @casl/ability: upgrade to the fixed version with the command below.
npm install @casl/ability@6.7.5Details
CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-1774[ADVISORY]
- https://github.com/stalniy/casl/pull/1093[WEB]
- https://github.com/stalniy/casl/commit/39da920ec1dfadf3655e28bd0389e960ac6871f4[WEB]
- https://cwe.mitre.org/data/definitions/1321.html[WEB]
- https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/Prototype_pollution[WEB]
- https://github.com/stalniy/casl[PACKAGE]
- https://github.com/stalniy/casl/tree/master/packages/casl-ability[WEB]
- https://www.kb.cert.org/vuls/id/458422[WEB]