PT-2026-57921 · Git+1 · Db
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
tanstack db versions prior to 0.6.9
Description
A remote attack is possible through the Alias Path Handler component. The
select() function in the src/query/compiler/select.ts file allows for the improperly controlled modification of object prototype attributes, a condition known as prototype pollution.Recommendations
Apply patch ac09b1177a100eafa85cba3cd09dd1f53f933ded to remediate the issue.
Exploit
Fix
Prototype Pollution
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Db