GHSA-r8c2-2qwq-94p6

    Dashboard / Vulnerabilities / GHSA-r8c2-2qwq-94p6

    GHSA-r8c2-2qwq-94p6

    Published: 20 Oct 2025Last Modified: 20 Oct 2025

    Summary: rollbar vulnerable to prototype pollution

    Details: ### Impact Prototype pollution potential with the utility function `rollbar/src/utility`.`set()`. No impact when using the published public interface. If application code directly imports `set` from `rollbar/src/utility` and then calls `set` with untrusted input in the second argument, it is vulnerable to prototype pollution. POC: ```js const obj = {}; require("rollbar/src/utility").set(obj, "__proto__.polluted", "vulnerable"); console.log({}.polluted !== undefined ? '[POLLUTION_TRIGGERED]':''); ``` ### Patches Fixed in version 2.26.5 and 3.0.0-beta5. ### Workarounds If application code directly imports `set` from `rollbar/src/utility`, ensure that the second argument does not receive untrusted input. ### References https://github.com/rollbar/rollbar.js/issues/1333#issuecomment-3353720946

    Affected packages

    Package

    Name: rollbar

    Purl: pkg:npm/rollbar

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.26.5

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-r8c2-2qwq-94p6 | CVE-DB