Intel

AIKIDO-2025-10985

altair-graphql-core is vulnerable to Prototype Pollution

Prototype Pollution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 26, 2025

70

High Risk

This Affects:

JSaltair-graphql-core
7.2.0 - 8.4.1
Fixed in 8.4.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Prototype Pollution vulnerability in the setByDotNotation utility function, where the lack of validation for user-controlled dot-notation paths allows an attacker to exploit it by injecting dangerous keys like __proto__, constructor, or prototype to mutate Object.prototype, potentially leading to Denial of Service (DoS), logic bypasses, or even Remote Code Execution (RCE).

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

altair-graphql-core is vulnerable to Prototype Pollution in versions 7.2.0 - 8.4.1.

How to fix this

Upgrade the altair-graphql-core library to the patch version.