CVE-2021-23433

MEDIUM

algoliasearch-helper < 3.6.2 - Prototype Pollution via SearchParameters._parseNumbers

Title source: llm
STIX 2.1

Description

The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties. Note that this vulnerability is only exploitable if the implementation allows users to define arbitrary search patterns.

Scores

CVSS v3 5.9
EPSS 0.0156
EPSS Percentile 72.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-1321
Status published
Products (2)
algolia/algoliasearch-helper < 3.6.2
npm/algoliasearch-helper 0 - 3.6.2npm
Published Nov 19, 2021
Tracked Since Feb 18, 2026