GHSA-529q-4j3p-7c5r

Suggest an improvement
Source
https://github.com/advisories/GHSA-529q-4j3p-7c5r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-529q-4j3p-7c5r/GHSA-529q-4j3p-7c5r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-529q-4j3p-7c5r
Aliases
Published
2025-09-27T06:30:52Z
Modified
2025-09-30T21:27:27Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
algoliasearch-helper is vulnerable to Prototype Pollution in _merge()
Details

Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype to be written even though doing so throws an error. In the "extreme edge-case" that the resulting error is caught, code injected into the user-supplied search parameter may be exeucted.

This is related to but distinct from the issue reported in CVE-2021-23433.

NOTE: This vulnerability is not exploitable in the default configuration of InstantSearch since searchParameters are not modifiable by users.

Database specific
{
    "cwe_ids":  [
        "CWE-1321"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-09-30T20:54:39Z",
    "nvd_published_at":  "2025-09-27T05:15:30Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / algoliasearch-helper

Package

Name
algoliasearch-helper
View open source insights on deps.dev
Purl
pkg:npm/algoliasearch-helper

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0-rc1
Fixed
3.11.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-529q-4j3p-7c5r/GHSA-529q-4j3p-7c5r.json"