Intel

AIKIDO-2025-10349

ra-data-local-storage is vulnerable to Prototype Pollution

Prototype Pollution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 4, 2025

75

High Risk

This Affects:

JSra-data-local-storage
3.9.0 - 5.8.2
Fixed in 5.8.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Prototype Pollution in multiple operations (delete, deleteMany, updateMany) due to insufficient validation of user-supplied input, allowing attackers to inject malicious properties like __proto__. An attacker could exploit this by manipulating these operations to modify the prototype of base objects, potentially leading to arbitrary code execution, denial of service, or privilege escalation.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

ra-data-local-storage is vulnerable to Prototype Pollution in versions 3.9.0 - 5.8.2.

How to fix this

Upgrade the ra-data-local-storage library to a patch version.