react-native-worklets is vulnerable to Prototype Pollution
43
Medium Risk
React Native Worklets clones plain JavaScript objects during serialization in clonePlainJSObject by assigning each source key directly onto a plain {} clone target. When the object being cloned contains a __proto__ key, that assignment mutates the clone's prototype instead of creating an own __proto__ property, corrupting the object Worklets later processes. When externally influenced data containing a __proto__ key reaches a shared value and is passed through this serialization path, React Native Worklets crashes, and persisted data can trigger the crash again on later access. The fix clones into a null-prototype object and materializes __proto__ as an own data property instead of assigning it through the default setter.
You are affected if you are using a version that falls within the vulnerable range and your application passes externally influenced data into a shared value that Worklets serializes.
react-native-worklets is vulnerable to Prototype Pollution in versions 0.5.0 - 0.12.1.
Upgrade the react-native-worklets library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.