Repository navigation
fix(deps): update dependency valibot to v1 [security] - #52
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.19.0→^1.0.0Valibot: record() issue paths can make flatten() throw for inherited Object property names
CVE-2026-59952 / GHSA-5qjj-4xww-7phc
More information
Details
Summary
valibot1.4.1 can throw aTypeErrorinside itsflatten()helper when validation issues contain attacker-controlled object keys such astoString,valueOf, orhasOwnProperty.The issue is reachable through normal
record()validation.record()intentionally filters__proto__,prototype, andconstructor, but it still accepts other own keys that collide with inheritedObject.prototypeproperties. If the record key schema or value schema rejects such an entry, Valibot creates an issue path containing that key. Passing the resulting issues to Valibot's documentedflatten()helper causesflatErrors.nested[dotPath]to resolve to the inherited method instead of an own error array, and the helper calls.push(...)on that function.This is not a global prototype pollution issue. The impact is availability/error handling: applications that validate user-controlled objects with
record()and flatten validation errors for API responses can crash the request path with aTypeErrorinstead of returning structured validation errors.Affected package
valibot1.4.1open-circle/valibot9bb6617Root cause
record()uses_isValidObjectKey()before validating record entries. The helper blocks the three classic prototype pollution keys:It does not block other inherited
Object.prototypenames such astoString,valueOf, andhasOwnProperty. These remain valid own JSON object keys and can appear in issue paths when either the record key schema or value schema rejects the entry.flatten()then creates nested error storage with an ordinary object:For a dot path such as
toString, this check reads the inheritedObject.prototype.toStringfunction:Because the inherited function is truthy,
flatten()calls.push(...)on a function and throwsTypeError: flatErrors.nested[dotPath].push is not a function.Impact
A remote attacker can trigger this if an application:
v.record(...);toString;flatten(result.issues)helper to prepare validation errors.This is a common pattern in API/form validation:
safeParse()collects issues andflatten()converts them into response-friendly error objects. Instead of a validation response, the request can hit an unexpected exception path.The same root cause can also affect manually constructed issues or other schemas that place inherited Object property names into dot paths. I am reporting the
record()path because it uses only public Valibot APIs and attacker-controlled JSON keys.Local reproduction
Run in a disposable directory:
Minimal example:
Observed output from
valibot@1.4.1:{ "name": "record value schema rejects attacker-controlled value", "key": "toString", "success": false, "issueCount": 1, "firstPath": ["toString"], "firstMessage": "Invalid type: Expected number but received \"not-a-number\"", "flattened": { "ok": false, "exception": "TypeError", "message": "flatErrors.nested[dotPath].push is not a function" } }The local PoC also reproduces the same exception for
valueOf,hasOwnProperty,isPrototypeOf,propertyIsEnumerable, andtoLocaleString. A control case with an ordinary key produces normal flattened errors.Duplicate checks performed before submission
valibotrelease is1.4.1and maps toopen-circle/valibot.gh api repos/open-circle/valibot/private-vulnerability-reportingreturned{"enabled":true}.npm auditfor a clean project containing onlyvalibot@1.4.1returned no vulnerabilities.1.2.0.valibot1.4.1returned no vulnerabilities.flatten toString,flatten hasOwnProperty,record toString,__proto__,constructor, andprototype pollutiondid not find a matching disclosure of thisrecord()issue-path /flatten()exception.open-circle/valibot#67added prototype pollution mitigation forrecord()by blacklisting__proto__,prototype, andconstructor; it does not coverflatten()collisions with other inherited property names.open-circle/valibot#1429is an open plain-object /record()type semantics PR and does not disclose thisflatten()exception behavior.Suggested remediation
Use null-prototype containers for flat error maps and/or perform own-property checks before appending:
flatErrors.nestedasObject.create(null).Object.prototype.hasOwnProperty.call(flatErrors.nested, dotPath)rather than truthiness.getDotPath()/flatten(), including inherited Object property names.flatten()with pathstoString,valueOf,hasOwnProperty,__proto__,prototype, andconstructor.Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
open-circle/valibot (valibot)
v1.4.2Compare Source
Many thanks to @Faze-up and @chatman-media for contributing to this release.
Intl.Segmenterfor non-primitive locales, preventing it from being recreated on everywords,minWords,maxWordsandnotWordsvalidation (pull request #1521)flattenmethod to handle issue path keys that collide withObject.prototypemembers liketoStringinstead of throwing aTypeError(pull request #1522)intersectschema to merge object keys that collide withObject.prototypemembers liketoStringinstead of failing to merge them (pull request #1522)v1.4.1Compare Source
intersectschema to infer correct input and output types for non-tuple array options instead ofnever(pull request #1478)v1.4.0Compare Source
Many thanks to @ksaurav24, @heiwen, @compulim, @ysknsid25, @alaycock-stripe, @IlyaSemenov, @wszgrcy, @LMGO, @yslpn, @EltonLobo07 and @Eronmmer for contributing to this release.
isoDateTimeSecondvalidation action to validate ISO date times with seconds (pull request #1418)toCamelCase,toKebabCase,toPascalCaseandtoSnakeCasetransformation actions to convert strings between common naming conventions (pull request #1457)ReadonlyOutputKeysandOutputWithReadonlytypes ofobjectschemas andWithReadonlytype ofrecordschemas to improve TypeScript type performance (pull request #1442)_LruCacheto use a TypeScriptprivatemethod instead of a#privateclass field to avoid runtime helpers in the transpiled output (pull request #1455)_isValidObjectKeyto useObject.prototype.hasOwnProperty.callinstead ofObject.hasOwnso the distributed output stays compatible with runtimes that lack the ES2022Object.hasOwnbuiltin (pull request #1421)flattenmethod to accept readonly issue arrays (pull request #1269)RangeErrorcaused by spreading large issue arrays (pull request #1437)creditCardvalidation action to reject Mastercard numbers with invalid lengths (pull request #1462)intersectschema to no longer mutate input values, allowing frozen objects and arrays to be merged (pull request #1463)v1.3.1Compare Source
MAC48_REGEX,MAC64_REGEXandMAC_REGEXto drop theiflag for better JSON Schema compatibility (pull request #1430)hashaction to use case-expanded character classes instead of theiflag (pull request #1430)v1.3.0Compare Source
Many thanks to @EskiMojo14, @yslpn, @alexilyaev, @idleberg, @BerkliumBirb and @frenzzy for contributing to this release.
guardtransformation action to narrow types using type predicates (pull request #1204)parseBooleantransformation action to parse boolean values from strings and other types (pull request #1251)isrcvalidation action to validate ISRC codes (pull request #1373)cachemethod for caching schema output by input (pull request #1170)domainvalidation action to validate domain names (pull request #1284)jwsCompactvalidation action to validate JWS compact strings (pull request #1348)creditCardvalidation action to allow 13-digit Visa card numbers (pull request #1347)isoTimestampvalidation action to allow optional space before UTC offset for PostgreSQLtimestamptzcompatibility (pull request #1195)v1.2.0Compare Source
Many thanks to @EskiMojo14, @makenowjust, @ysknsid25 and @jacekwilczynski for contributing to this release.
toBigint,toBoolean,toDate,toNumberandtoStringtransformation actions (pull request #1212)examplesaction to add example values to a schema (pull request #1199)getExamplesmethod to extract example values from a schema (pull request #1199)isbnvalidation action to validate ISBN-10 and ISBN-13 strings (pull request #1097)RawCheckAddIssue,RawCheckContext,RawCheckIssueInfo,RawTransformAddIssue,RawTransformContextandRawTransformIssueInfotypes for better developer experience withrawCheckandrawTransformactions (pull request #1359)EMOJI_REGEXused byemojiactionv1.1.0Compare Source
Many thanks to @EltonLobo07, @sacrosanctic, @muningis, @EskiMojo14, @MOZGIII, @vktrl and @jasperteo for contributing to this release.
messagemethod to overwrite local error message configuration of a schema (pull request #1103)summarizemethod to summarize issues into a pretty-printable multi-line string (pull request #1158)getTitle,getDescriptionandgetMetadatamethods to extract metadata of a schema (pull request #1154)minEntriesandmaxEntriesvalidation action to validate number of object entries (pull request #1100)entriesandnotEntriesvalidation action to validate number of object entries (pull request #1156)parseJsonandstringifyJsontransformation action to parse and stringify JSON (pull request #1137)flavortransformation action to flavor the output type of a schema (pull request #950)multipleOfvalidation action (pull request #1164)variantandvariantAsyncschema to improve performance by aborting validation of discriminators early (pull request #1110)NanoIDActionandNanoIDIssueinterface toNanoIdActionandNanoIdIssue(pull request #1171)MarkOptionaltype to fix input and output type of objects in edge cases (issue #1176)v1.0.0Compare Source
This is a summary of the changes between v0 and v1. Many thanks to everyone who contributed to this release.
assertmethod to assert values (issue #862)checkItemsAsyncaction (pull request #856)graphemes,maxGraphemes,minGraphemesandnotGraphemesaction (pull request #853)words,maxWords,minWordsandnotWordsactionargsandreturnsaction to transform functions (issue #243)rfcEmailaction to validate RFC 5322 email addresses (pull request #912)gtValueandltValueaction for greater than and less than validation (pull request #978, #985)valuesandnotValuesaction for easier multi-value validation (pull request #919)slugaction to validate URL slugs (pull request #910)ReadonlyMapandReadonlySettoreadonlyaction (issue #1059)entriesFromObjectsutil to improve tree shaking (pull request #1023)pipeandpipeAyncmethod to support unlimited pipe items of same input and output type (issue #852)@__NO_SIDE_EFFECTS__notation to improve tree shaking (pull request #995)exactOptionalandexactOptionalAsyncschema (PR #1013)minValueandmaxValueforNaN(pull request #843)nullable,nullableAsync,nullish,nullishAsync,optional,optionalAsync,undefinedableandundefinedableAsyncfor undefined default value (issue #878)partialCheckandpartialCheckAsyncaction to add.pathListproperty in a type-safe wayfindItemaction to support type predicates (issue #867)looseObject,looseObjectAsync,object,objectAsync,objectWithRest,objectWithRestAsync,strictObjectandstrictObject(PR #1013)optionalandoptionalAsyncwhen used within an object schema (PR #1013)MarkOptionaltype to fix order of entries and TS error when using generic schemas (issue #1021)VariantOptionandVariantOptionAsynctype to fix TS error when using generic schemas (issue #842)variantandvariantAsyncto support optional discriminators usingexactOptional,exactOptionalAsync,optional,optionalAsync,nullishornullishAsync_addIssueto not ignore empty strings as error message (pull request #1065)ISO_DATE_TIME_REGEXandISO_TIMESTAMP_REGEXto support space as separator (pull request #1064)pipeandpipeAsyncto be readonly by defaultforward,forwardCheck,partialCheckandpartialCheckAsyncto improve TypeScript performance (issue #987)DECIMAL_REGEXto support floats that start with a dot (pull request #1086)bytes,maxBytes,minBytesandnotBytesactionnonOptional,nonOptionalAsync,nonNullable,nonNullableAsync,nonNullishandnonNullishAsyncschema in edge cases (issue #909)anyinPathKeystype (issue #929)keyofmethod for objects with many keys (pull request #988)enum_schema (pull request #941)partialCheckandpartialCheckAsyncaction for typed data with issuesv0.42.1Compare Source
_runpropertyv0.42.0Compare Source
Many thanks to @ajfhs812, @andrew-d-jackson and @declanlscott for contributing to this release.
metadataaction to add custom metadata to a schematitlemetadata action to add a title to a schema (discussion #826)decimalaction to validate integer and float strings (pull request #823)decimalaction todigits(pull request #823)NoPipetype toSchemaWithoutPipeIssueDotPathtype (issue #814)v0.41.0Compare Source
Many thanks to @EltonLobo07, @ZerNico, @Andarist, @ruiaraujo012 and @merodiro for contributing to this release.
referenceproperty of all action base types to be less strict (issue #799)variantandvariantAsyncto improve performance and issues generation for nested variants with different discriminators (pull request #809)v0.40.0Compare Source
Many thanks to @jasperteo, @alecmev and @cruzdanilo for contributing to this release.
nanoidaction to validate Nano IDs (pull request #789)undefinedableandundefinedableAsyncschema (issue #385)v0.39.0Compare Source
Many thanks to @tpetry, @incompletude, @ComradeVanti, @istonikula and @ShlokDesai33 for contributing to this release.
exactOptionalPropertyTypesconfig (issue #385)IssueDotPathtype forpipeandpipeAsyncmethod (issue #793)IssueDotPathtype forvariantandvariantAsyncschema (issue #700)v0.38.0Compare Source
Many thanks to @EltonLobo07, @samuba, @alecmev, @gflohr, @threehams and @carcinocron for contributing to this release.
expectsandexpectedproperty by enclosing combined values in parenthesesoptional,optionalAsync,nullishandnullishAsyncschemas in objectsTuplePathandQuestionMarkSchematype (issue #659, #776)pipeandpipeAsyncmethod (pull request #785)v0.37.0Compare Source
Many thanks to @morinokami, @xcfox, @devcaeg, @shayneo, @Sandros94, @slevithan, @thecotne and @EltonLobo07 for contributing to this release.
base64action to validate Base64 strings (pull request #644)descriptionmetadata action (pull request #747)pipeandpipeAsyncmethod (pull request #747)HEXADECIMAL_REGEX(pull request #666)unknown[]inLengthInputtype toArrayLike<unknown>ArrayInputandContentInputtype to useMaybeReadonlyEMOJI_REGEXto be more accurate and strict (pull request #666)fallbackandfallbackAsyncmethod for specific schemas (pull request #752)fallbackAsyncmethod for async schemas (pull request #732)v0.36.0Compare Source
Many thanks to @N0tExisting, @ksv90, @peterbe, @foster-hangdaan and @zougari47 for contributing to this release.
normalizeaction to normalize strings (issue #691)entriesFromListutilentriesFromListutil (issue #492)keyproperty toSetPathItemtype to improve DX (issue #693, #694)FunctionReferencetype and refactor codev0.35.0Compare Source
Many thanks to @jindong-zhannng, @dyljhd and @TeChn4K for contributing to this release.
pipeandpipeAsyncmethod to 19 (issue #643)v0.34.0Compare Source
Many thanks to @Saeris, @Jimdooz, @Kenzo-Wada and @sillvva for contributing to this release.
file,functionandpromiseschemaawaitAsyncaction to await promise in pipelineoperationproperty tofilterItems,findItem,mapItems,reduceItemsandsortItemactionactionargument offilterItems,findItem,mapItems,reduceItemsandsortItemaction tooperationactionargument and property oftransformandtransformAsyncaction tooperation_stringifyutilv0.33.3Compare Source
Many thanks to @Demivan for contributing to this release.
_isPartiallyTypedutil ofpartialCheckandpartialCheckAsyncactionv0.33.2Compare Source
Many thanks to @allezxandre for contributing to this release.
v0.33.1Compare Source
partialCheckandpartialCheckAsyncactionv0.33.0Compare Source
Many thanks to @Demivan, @ruiaraujo012, @Karakatiza666, @micahjon, @unlinking, @demarchenac, @xsjcTony, @ziyak97 and @Lukasz17git for contributing to this release.
partialCheckandpartialCheckAsyncaction (issue #76, #145, #260)checkItems,filterItems,findItem,mapItems,reduceItemsandsortItemaction (issue #595)everyandsomeaction toeveryItemandsomeItem_isAllowedObjectKeyto_isValidObjectKeyand add check for inherited propertiesRecordPathItemandTuplePathItemtype and refactor codereceivedproperty of issue indateschema for invalid dates (issue #654)v0.32.0Compare Source
Many thanks to @ruiaraujo012, @jansedlon, @ksjitendra18 and @megacherry for contributing to this release.
rawCheck,rawCheckAsync,rawTransformandrawTransformAsyncaction (issue #597)FlatErrorstype for better developer experience (discussion #640)pipeandpipeAsyncmethod to mark output as untyped only when necessary (discussion #613)skipPipeoption fromConfigtype and refactor librarythisreference inlooseTuple,looseTupleAsync,strictTuple,strictTupleAsync,tuple,tupleAsync,tupleWithRestandtupleWithRestAsyncschema (pull request #649)optionskey inEnumSchemainterfacev0.31.1Compare Source
Many thanks to @Omochice for contributing to this release.
v0.31.0Compare Source
Many thanks to @Afsoon, @AlexXanderGrib, @Andarist, @AndreyYolkin, @ariskemper, @Demivan, @DylanThomasFr, @EltonLobo07, @GabrielHangor, @Hugos68, @IlyaSemenov, @MohammedEsafi, @MrGeniusProgrammer, @Saeris, @Sandros94, @Sec-ant, @alexbit-codemod, @ammarriq, @anuraghazra, @arybitskiy, @bingtsingw, @brandonpittman, @brenelz, @chertik77, @chimame, @christophsturm, @dboune, @devcaeg, @dusty, @fredericoo, @gmaxlev, @homersimpsons, @jansedlon, @jchatard, @joshwashywash, @jsudelko, @juliusmarminge, @kovalchukq, @linkb15, @lukemorton, @macarie, @morgante, @mtt-artis, @mutewinter, @mxdvl, @nakanoasaservice, @naveen-bharathi, @sacrosanctic, @samualtnorman, @saturnonearth, @seren5240, @sillvva, @ssalbdivad, @vladshcherbin, @xcfox, @yudinmaxim, @znycheporuk and many others for contributing to this release.
To migrate from an older version, please see the official migration guide and our announcement post.
v0.30.0Compare Source
Many thanks to @Saeris, @ariskemper, @mxdvl, @romeerez and @niccholaspage for contributing to this release.
DefaultandDefaultAsynctype and refactor codebaseFallbackandFallbackAsynctype and refactor codebaseisOfTypetype guard util to check the type of an objectgetDefaultsandgetDefaultsAsyncmethod (pull request #259)getFallbacksandgetFallbacksAsyncmethod (pull request #259)typetointerface(pull request #259, #451)safeParseandsafeParseAsyncmethodNestedPathtype offlattenfor async schemas (issue #456)DefaultValuetype for transformed valuesv0.29.0Compare Source
Many thanks to @Mini-ghost, @ivands and @Demivan for contributing to this release.
everyandsomepipeline validation actioninputof schema togetterfunction ofrecursiveandrecursiveAsyncschema (pull request #441)transformandtransformAsyncmethod to only run transformations if there are no issues (issue #436)recursiveandrecursiveAsyncschema tolazyandlazyAsync(issue #440)i18nutil when usingsetSchemaMessagev0.28.1Compare Source
Many thanks to @compulim for contributing to this release.
unionandunionAsyncschema for transformed inputs (issue #420)v0.28.0Compare Source
Many thanks to @LorisSigrist, @samuelstroschein, @gmaxlev, @thundermiracle, @ivanhofer, @CanRau, @zkulbeda, @lucaschultz, @paoloricciuti, @hyunbinseo, and @bertez for contributing to this release.
numberandbiginttoPicklistOptionstype (issue #378)forwardAsyncmethod (issue #412)v0.27.1Compare Source
Many thanks to @Omochice for contributing to this release.
v0.27.0Compare Source
Many thanks to @pschiffmann for contributing to this release.
NonNullable,NonNullishandNonOptionaltypeNonNullableInput,NonNullableOutput,NonNullishInput,NonNullishOutput,NonOptionalInputandNonOptionalOutputtypeomit,omitAsync,pickandpickAsyncschema to also allow read-only object keys (issue #380)pipeargument atintersectandintersectAsyncschemav0.26.0Compare Source
Many thanks to @WtfJoke, @dboune, @alexabw and @aypotu for contributing to this release.
enum_andenumAsyncschema by caching valuesunion,unionAsync,variantandvariantAsyncschema to improve developer experiencegetDefaults,getDefaultsAsync,getFallbacksandgetFallbacksAsyncschema for falsy but notundefinedvalues (issue #356)pipeargument atunion,unionAsync,variantandvariantAsyncschemaunion,unionAsync,variantandvariantAsyncschema (issue #364)startsWithvalidation action (pull request #375)Migration guide
The changes in
union,unionAsync,variantandvariantAsyncare breaking changes and may result in different behavior when returning issues. Please create an issue if you have questions about this.v0.25.0Compare Source
Many thanks to @ariskemper, @ewautr, @cuberoot @lo1tuma and @richardvanbergen for contributing to this release.
creditCard,decimal,hash,hexadecimal,hexColorandoctalpipeline validation action (pull request #292, #304, #307, #308, #309)pipeparameter tointersect,intersectAsync,union,unionAsync,variantandvariantAsyncschema (discussion #297)variantandvariantAsyncschema (issue #310)variantandvariantAsyncschema is missing (issue #235, #303)PicklistOptionstype and generics ofpicklistandpicklistAsyncschemav0.24.1Compare Source
Many thanks to @NotWorkingCode for contributing to this release.
objectandobjectAsyncentries with default value (issue #286)nullable,nullableAsync,nullish,nullishAsync,optionalandoptionalAsyncschema with default value (issue #286)v0.24.0Compare Source
Many thanks to @genki and @NotWorkingCode for contributing to this release.
specialschema as key ofrecordschema (issue #291)specialandspecialAsyncschema as key ofrecordAsyncschema (issue #291)v0.23.0Compare Source
Many thanks to @ariskemper, @ivands and @emilgpa for contributing to this release.
bicvalidation function (pull request #284)mac,mac48andmac64validation function (pull request #270)PicklistOptions,UnionOptionsandUnionOptionsAsynctype from tuple to array (issue #279)IntersectOptions,IntersectOptionsAsync,UnionOptionsandUnionOptionsAsynctype to support readonly values (issue #279)ObjectInputandObjectOutputtype (issue #242)v0.22.0Compare Source
Many thanks to @ecyrbe, @Demivan, @GriefMoDz, @demarchenac, @TFX0019, @AbePlays, @irg1008, @skotenko, @dukeofsoftware, @xxxhussein, @JortsEnjoyer0, [@Karakatiza666](https://redirect.github.com/Karakati
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.