Intel

AIKIDO-2025-10826

graphql-upload-minimal is vulnerable to Prototype Pollution

Prototype Pollution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 19, 2025

46

Medium Risk

This Affects:

jsgraphql-upload-minimal
0.1.0 - 1.6.2
Fixed in 1.6.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a prototype pollution in the deepSet util function, which could allow attackers to manipulate object properties and impact application behavior.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

graphql-upload-minimal is vulnerable to Prototype Pollution in versions 0.1.0 - 1.6.2.

How to fix this

Upgrade the graphql-upload-minimal library to the patch version.