GHSA-8cw4-87c7-c6xx
Dashboard / Vulnerabilities / GHSA-8cw4-87c7-c6xx
Summary: node-csv: Prototype replacement still reachable via columns path
Details: ### Impact With columns: true and group_columns_by_name: true, a duplicated __proto__ header causes the duplicate-column branch to assign an array to obj['__proto__'], invoking the __proto__ setter and replacing the parsed record object's prototype with attacker-controlled data. Fixed in 7.0.2 (Object.hasOwn duplicate check + Object.defineProperty assignment). ### Patches The problem been patched. ### Workarounds Disable usage of both the columns and group_columns_by_name options. ### References issue #496, PR #497
References: https://github.com/adaltas/node-csv/security/advisories/GHSA-8cw4-87c7-c6xx, https://nvd.nist.gov/vuln/detail/CVE-2026-85063, https://github.com/adaltas/node-csv/issues/496, https://github.com/adaltas/node-csv/pull/497, https://github.com/adaltas/node-csv/commit/eb4d1484589c976dcb977db8dd0b90e015a6f66e, https://github.com/adaltas/node-csv
Affected packages
Package
Name: csv-parse
Purl: pkg:npm/csv-parse
Affected ranges
Type: SEMVER
Events:
