GHSA-8hq7-ggx2-cc6m: Medium severity npm/msgpack5 vulnerability

Published Oct 8, 2026
·
Updated

Impact

Passing an empty or partial options object disables the default protoAction: 'error' protection. A map containing a proto key can then replace the prototype of the decoded object, potentially changing inherited properties or causing unexpected behavior in downstream code.

Only the decoded object's prototype is affected; this does not modify Object.prototype globally.

Patches

Options are now merged with secure defaults without modifying the caller's object. Unsupported protoAction values are rejected.

Workarounds

Explicitly set protoAction: 'error' whenever constructing a msgpack5 instance, and validate decoded values before use.

Affected Software

1 affected componentFixes available
npm/msgpack5<6.1.0
6.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/msgpack5 to a version that resolves this vulnerability.

    Fixed in 6.1.0
  2. Configuration

    Explicitly set protoAction to 'error' whenever constructing a msgpack5 instance; do not rely on empty or partial options objects, which disable this protection.

    msgpack5 protoAction = error
  3. Compensating control

    Validate decoded values before using them.

Event History

Oct 8, 2026
Advisory Published
via GitHub·05:39 PM
Data Sourced
via GitHub·05:39 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments using npm/msgpack5 are exposed when they construct an instance with an empty or partial options object, because that disables the default protoAction: 'error' protection. The issue affects decoded maps containing a __proto__ key.

2

What must an attacker provide to trigger the vulnerable behavior?

An attacker must be able to supply MessagePack data that is decoded by the affected instance and contains a map with a __proto__ key. Exploitation can replace the prototype of the decoded object, which may alter inherited properties or cause unsafe downstream behavior.

3

Does this pollute Object.prototype globally?

No. The prototype replacement is limited to the individual decoded object and does not modify Object.prototype globally.

4

What can be done before applying the patch?

Explicitly set protoAction: 'error' whenever constructing a msgpack5 instance. Also validate decoded values before using them in downstream code.

5

What changed in the patched release?

The patch merges supplied options with secure defaults without modifying the caller's options object, and it rejects unsupported protoAction values. The referenced release is v6.1.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203