Vulnerabilities/

Prototype Pollution in algoliasearch-helper

Severity:
High

Description

The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties.

Recommendation

Update the algoliasearch-helper package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
algoliasearch-helper
Anything's wrong? Let us know Last updated on January 27, 2023