GHSA-8cw4-87c7-c6xxMedium
node-csv: Prototype replacement still reachable via columns path
🔗 CVE IDs covered (1)
📋 Description
Impact
With columns: true and group_columns_by_name: true, a duplicated proto header causes the duplicate-column branch to assign an array to obj['proto'], invoking the proto setter and replacing the parsed record object's prototype with attacker-controlled data. Fixed in 7.0.2 (Object.hasOwn duplicate check + Object.defineProperty assignment).
Patches
The problem been patched.
Workarounds
Disable usage of both the columns and group_columns_by_name options.
References
issue #496, PR #497
🎯 Affected products1
- npm/csv-parse:< 7.0.2
🔗 References (6)
- https://github.com/adaltas/node-csv/security/advisories/GHSA-8cw4-87c7-c6xx
- https://nvd.nist.gov/vuln/detail/CVE-2026-85063
- https://github.com/adaltas/node-csv/issues/496
- https://github.com/adaltas/node-csv/pull/497
- https://github.com/adaltas/node-csv/commit/eb4d1484589c976dcb977db8dd0b90e015a6f66e
- https://github.com/advisories/GHSA-8cw4-87c7-c6xx