GHSA-8hq7-ggx2-cc6mMediumCVSS 6.5
msgpack5: Partial options disable prototype protection
🔗 CVE IDs covered (1)
📋 Description
Impact
Passing an empty or partial options object disables the default protoAction: 'error' protection. A map containing a __proto__ key can then replace the prototype of the decoded object, potentially changing inherited properties or causing unexpected behavior in downstream code.
Only the decoded object's prototype is affected; this does not modify Object.prototype globally.
Patches
Options are now merged with secure defaults without modifying the caller's object. Unsupported protoAction values are rejected.
Workarounds
Explicitly set protoAction: 'error' whenever constructing a msgpack5 instance, and validate decoded values before use.
🎯 Affected products1
- npm/msgpack5:< 6.1.0