Description
This is critical vulnerability, as it allows to run arbitrary code on any server using superjson input, including a Blitz.js server, without prior authentication or knowledge. Attackers gain full control over the server so they could steal and manipulate data or attack further systems.
Recommendation
Update the superjson package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.8.1
- Patched version(s): 1.8.1
References
Could your website be exposed too?
SmartScanner can check your website for Prototype Pollution leading to Remote Code Execution in superjson and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Joplin Remote Code Execution - CVE-2022-40277
- @saltcorn/server Remote Code Execution (RCE) / SQL injection via prototype pollution by manipulating `lang` and `defst - Vulnerability
- angular-base64-upload vulnerable to unauthenticated remote code execution - CVE-2024-42640
- Angular Expressions - Remote Code Execution - CVE-2021-21277


