Intel

AIKIDO-2024-10137

json-joy is vulnerable to Prototype Pollution

Prototype Pollution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 21, 2024

50

Medium Risk

This Affects:

JSjson-joy
1.0.0 - 16.8.0
Fixed in 16.9.0
Are you affected? Scan for Free

TL;DR

Affected versions of json-joy are vulnerable to a prototype pollution vulnerability via the o.set(...) / set(...) function.

Who does this affect?

You are affected if you use a vulnerable version of json-joy, and you directly or indirectly use the o.set(...) / set(...) function.

Background info

json-joy is vulnerable to Prototype Pollution in versions 1.0.0 - 16.8.0.

How to fix this

Upgrade json-joy to a patch version.