3.26.0
10 years ago
3 months ago
Known vulnerabilities in the algoliasearch-helper package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
algoliasearch-helper is a Helper for implementing advanced search features with algolia Affected versions of this package are vulnerable to Prototype Pollution in the This is related to but distinct from the issue reported in CVE-2021-23433. NOTE: This vulnerability is not exploitable in the default configuration of How to fix Prototype Pollution? Upgrade | >=2.0.0-rc1 <3.11.2 |
algoliasearch-helper is a Helper for implementing advanced search features with algolia Affected versions of this package are vulnerable to Prototype Pollution due to use of the Note that this vulnerability is only exploitable if the implementation allows users to define arbitrary search patterns. PoC
How to fix Prototype Pollution? Upgrade | <3.6.2 |