rulesync is vulnerable to Prototype Pollution
61
Medium Risk
An improper input validation issue in rulesync Gemini CLI policy conversion allowed crafted permission rules to trigger prototype pollution through reserved JavaScript object keys, bypass JSON field-boundary matching through unsafe glob-to-regex translation, or create unintended match-all shell permissions through empty or wildcard bash patterns. This could enable attackers controlling policy files to corrupt permission state, weaken access restrictions, or silently grant overly broad command execution rights.
You are affected if you are using a version that falls within the vulnerable range.
rulesync is vulnerable to Prototype Pollution in versions 8.0.0 - 8.5.0.
Upgrade the rulesync library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant