GHSA-4q55-j62x-fr9h: Npm/devalue vulnerability
This is another instance of https://github.com/sveltejs/devalue/security/advisories/GHSA-mwv9-gp5h-frr4, where some payloads could cause parse to create objects with a proto own property. This on its own is not enough to cause prototype pollution, and indeed this is actually how JSON.parse works, but we decided to be a little more defensive here and not allow the creation of objects with proto own-properties. It is very unlikely for this to cause any issues.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/devalueto a version that resolves this vulnerability.Fixed in 5.9.3
Event History
Frequently Asked Questions
Does creating an own `__proto__` property cause prototype pollution by itself?
No. The advisory states that this behavior alone is not enough to cause prototype pollution; it is also how `JSON.parse` behaves.
What would an attacker need to do to trigger the behavior?
They would need to supply a payload that is processed by `parse` and causes it to create an object with an own `__proto__` property.
How urgent is remediation?
The advisory says it is very unlikely that this behavior will cause issues. A defensive change was released in devalue v5.9.3 to prevent creation of objects with own `__proto__` properties.