Revisiting Prototype Pollution vulnerabilities in JavaScript, Disruptive Node.js 22.5.0 version get fixed, Nuxt security, and Nuxt v4.0​

​​Understanding and Preventing Prototype Pollution in Node.js​ — A short but practical walkthrough of Prototype Pollution in Node.js: what it is, how it works, and how to prevent it. Includes a real-world example nodejs-security.com

prototype pollution

Headlines

​🚧 Node.js 22.5.0 included a bug that broke many builds — A bug in Node.js 22.5.0 caused many CI setups to fail their npm and yarn build workflows. Upgrade to Node.js 22.5.1 for a fix nodejs

​$ node —experimental-permission —allow-fs-write=​ — On-going discussion on the Node.js repository about verbose runtime warning when wildcards are used in filesystem trust policy github

​import sqlite from ‘node:sqlite’​ — SQLite is coming to a Node.js runtime version near you with initial support being merged in Node.js core github

Carlos Sousa improves Node.js URL.canParse performance by 50%​ github

​Yagiz Nizipli​ with more performance magic: fs.dir 100% faster​ github

​ 🚨 Lodash prototype pollution vulnerabilities, upgrade to >= 4.17.17 affected versions are vulnerable through the zipObjectDeep function due to improper user input sanitization in the baseZipObject function:

lodash prototype pollution vulnerabilities

Nuxt Security module celebrates 1,000,000 downloads — Congratulations to Jakub Andrzejewski for achieving this milestone and helping us ship secure Vue.js server-side applications githubNuxt security module

Nuxt v4.0 about to ship 🚀 — continuing with Nuxt updates, the next major version of Nuxt is getting prepared for a release github ​ ​Firebase + Fastify = best friends? — A step-by-step guide to enable HTTP webhooks on Google’s Firebase platform running the Fastify framework as a Firebase function lirantal.com

On npm

  • oxlint​ - More Rust tooling for the JavaScript ecosystem, the Oxidation Compiler brings fast linters, recording 50 times faster than ESLint benchmark
  • fastify-helmet​ - fastify-helmet helps you secure your Fastify apps by setting important security headers
  • kysely 0.27.4 release 🎉 - kysely, the strongly-typed ORM with a new version and many bug fixes

New Security Vulnerabilities

Hiring


Node.js Security Newsletter

Subscribe to get everything in and around the Node.js security ecosystem, direct to your inbox.

    JavaScript & web security insights, latest security vulnerabilities, hands-on secure code insights, npm ecosystem incidents, Node.js runtime feature updates, Bun and Deno runtime updates, secure coding best practices, malware, malicious packages, and more.