GHSA-8hq7-ggx2-cc6m: Medium severity npm/msgpack5 vulnerability
Impact
Passing an empty or partial options object disables the default protoAction: 'error' protection. A map containing a proto key can then replace the prototype of the decoded object, potentially changing inherited properties or causing unexpected behavior in downstream code.
Only the decoded object's prototype is affected; this does not modify Object.prototype globally.
Patches
Options are now merged with secure defaults without modifying the caller's object. Unsupported protoAction values are rejected.
Workarounds
Explicitly set protoAction: 'error' whenever constructing a msgpack5 instance, and validate decoded values before use.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/msgpack5to a version that resolves this vulnerability.Fixed in 6.1.0 - Configuration
Explicitly set protoAction to 'error' whenever constructing a msgpack5 instance; do not rely on empty or partial options objects, which disable this protection.
msgpack5 protoAction = error - Compensating control
Validate decoded values before using them.
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using npm/msgpack5 are exposed when they construct an instance with an empty or partial options object, because that disables the default protoAction: 'error' protection. The issue affects decoded maps containing a __proto__ key.
What must an attacker provide to trigger the vulnerable behavior?
An attacker must be able to supply MessagePack data that is decoded by the affected instance and contains a map with a __proto__ key. Exploitation can replace the prototype of the decoded object, which may alter inherited properties or cause unsafe downstream behavior.
Does this pollute Object.prototype globally?
No. The prototype replacement is limited to the individual decoded object and does not modify Object.prototype globally.
What can be done before applying the patch?
Explicitly set protoAction: 'error' whenever constructing a msgpack5 instance. Also validate decoded values before using them in downstream code.
What changed in the patched release?
The patch merges supplied options with secure defaults without modifying the caller's options object, and it rejects unsupported protoAction values. The referenced release is v6.1.0.