Intel

AIKIDO-2026-10520

rulesync is vulnerable to Prototype Pollution

Prototype Pollution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 23, 2026

61

Medium Risk

This Affects:

JSrulesync
8.0.0 - 8.5.0
Fixed in 8.6.0
Are you affected? Scan for Free

TL;DR

An improper input validation issue in rulesync Gemini CLI policy conversion allowed crafted permission rules to trigger prototype pollution through reserved JavaScript object keys, bypass JSON field-boundary matching through unsafe glob-to-regex translation, or create unintended match-all shell permissions through empty or wildcard bash patterns. This could enable attackers controlling policy files to corrupt permission state, weaken access restrictions, or silently grant overly broad command execution rights.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

rulesync is vulnerable to Prototype Pollution in versions 8.0.0 - 8.5.0.

How to fix this

Upgrade the rulesync library to the patch version.