MEDIUM5.9
GHSA-xcg2-9pp4-j82x
rollbar vulnerable to Prototype Pollution in merge()
Quick fix
GHSA-xcg2-9pp4-j82x — rollbar: upgrade to the fixed version with the command below.
npm install rollbar@2.26.5Details
### Impact
Prototype pollution vulnerability in merge(). If application code calls `rollbar.configure()` with untrusted input, prototype pollution is possible.
### Patches
Fixed in 2.26.5 and 3.0.0-beta5.
### Workarounds
Ensure that values passed to `rollbar.configure()` do not contain untrusted input.
### References
Fixed in https://github.com/rollbar/rollbar.js/pull/1394 (2.26.x) and https://github.com/rollbar/rollbar.js/pull/1390 (3.x)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/rollbar/rollbar.js/security/advisories/GHSA-xcg2-9pp4-j82x[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-62517[ADVISORY]
- https://github.com/rollbar/rollbar.js/pull/1390[WEB]
- https://github.com/rollbar/rollbar.js/pull/1394[WEB]
- https://github.com/rollbar/rollbar.js/commit/61032fe6c208b71e249514800808a54bcb8cb8bb[WEB]
- https://github.com/rollbar/rollbar.js/commit/d717def8b68f4a947975d0aebb729869cdb2d343[WEB]
- https://github.com/rollbar/rollbar.js[PACKAGE]