Vulnerabilities/

Prototype Pollution leading to Remote Code Execution in superjson

Severity:
High

Description

This is critical vulnerability, as it allows to run arbitrary code on any server using superjson input, including a Blitz.js server, without prior authentication or knowledge. Attackers gain full control over the server so they could steal and manipulate data or attack further systems.

Recommendation

Update the superjson package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
superjson
Anything's wrong? Let us know Last updated on November 01, 2023