react-native-worklets@0.13.0-nightly-20260831-805a4501e

The React Native multithreading library

  • latest version

    0.13.0

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    11 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the react-native-worklets package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Prototype Pollution

    react-native-worklets is a The React Native multithreading library

    Affected versions of this package are vulnerable to Prototype Pollution via the cloneObjectProperties serialization path in packages/react-native-worklets/src/memory/serializable.native.ts. An attacker can crash a React Native application by supplying an object with a __proto__ property that is passed through this cloning code. When that malformed data is serialized and later processed by Worklets, the application can terminate, causing a remotely triggered denial of service and potentially a persistent crash if the attacker-controlled value is stored and reloaded.

    How to fix Prototype Pollution?

    Upgrade react-native-worklets to version 0.12.2, 0.13.0 or higher.

    <0.12.2>=0.13.0-nightly-20260812-0f8cf6dcc <0.13.0