Intel

AIKIDO-2025-10083

@rpldy/uploady is vulnerable to Prototype Pollution

Prototype PollutionCVE-2024-57082

72

High Risk

This Affects:

JS@rpldy/uploady
1.0.17 - 1.9.0
Fixed in 1.9.1

TL;DR

Affected versions of this package are affected by a design flaw that arises from improper handling of objects, particularly during the merging, cloning, or validation of plain objects. This flaw can allow attackers to modify an object's prototype by injecting or manipulating its properties. As a result, this can lead to unexpected behavior in all objects, potentially allowing attackers to bypass security checks and escalate their privileges.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@rpldy/uploady is vulnerable to Prototype Pollution in versions 1.0.17 - 1.9.0.

How to fix this

Upgrade the @rpldy/uploady library to the patch version.