Synchrony deobfuscator is a javascript cleaner & deobfuscator. A __proto__
pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitrary code execution. A __proto__
pollution vulnerability exists in the LiteralMap
transformer allowing crafted input to modify properties in the Object prototype. A fix has been released in deobfuscator@2.4.4
. Users are advised to upgrade. Users unable to upgrade should launch node with the [–disable-proto=delete][disable-proto] or [–disable-proto=throw][disable-proto] flags
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Synchrony | Relative | 2.0.1 (including) | 2.4.4 (excluding) |