Description
valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.0.0
References
Could your website be exposed too?
SmartScanner can check your website for Exposure of Resource to Wrong Sphere in valib and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Exposure of Sensitive Information to an Unauthorized Actor in nanoid - CVE-2021-23566
- bson-objectid contains Improper input validation - CVE-2019-19729
- websocket-driver: Resource limit bypass via message compression - CVE-2026-54490
- Sensitive Data Exposure in msrcrypto - CVE-2018-8319


