VDB
Sign up
HIGH7.7

GHSA-xp9c-82x8-7f67

Prototype Pollution in Node-Red

Quick fix

GHSA-xp9c-82x8-7f67 — @node-red/runtime: upgrade to the fixed version with the command below.

npm install @node-red/runtime@1.2.8

Details

### Impact

Node-RED 1.2.7 and earlier contains a Prototype Pollution vulnerability in the admin API. A badly formed request can modify the prototype of the default JavaScript Object with the potential to affect the default behaviour of the Node-RED runtime.

### Patches

The vulnerability is patched in the 1.2.8 release.

### Workarounds

A workaround is to ensure only authorised users are able to access the editor url.

### For more information If you have any questions or comments about this advisory: * Email us at [team@nodered.org](mailto:team@nodered.org)

### Acknowledgements

Thanks to the Tencent Woodpecker Security Team for disclosing this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@node-red/runtime
Introduced in: 0Fixed in: 1.2.8
Fixnpm install @node-red/runtime@1.2.8

References