Description
The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties.
Recommendation
Update the algoliasearch-helper package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.6.2
- Patched version(s): 3.6.2
References
Related Issues
- algoliasearch-helper is vulnerable to Prototype Pollution in _merge() - CVE-2025-3193
- Prototype Pollution in the merge and clone helper methods - CVE-2021-39227
- Prototype pollution in min-dash - CVE-2021-23460
- json-schema is vulnerable to Prototype Pollution - CVE-2021-3918
You might also like:
- Tags:
- npm
- algoliasearch-helper
Anything's wrong? Let us know Last updated on January 27, 2023


