Executive brief
algoliasearch-helper is a JavaScript library used to implement advanced search features with the Algolia search service. A prototype pollution vulnerability in the _merge() function allows attackers to inject code into JavaScript object prototypes under specific conditions, potentially leading to code execution or application malfunction. The vulnerability requires an edge case where an application catches errors during search parameter processing and remains unexploitable in Algolia's default InstantSearch configuration.
Technical details
The vulnerability is a prototype pollution issue in the _merge() function within merge.js affecting versions 2.0.0-rc1 through 3.11.2. The vulnerable code attempts to recursively merge user-supplied search parameters into target objects without properly blocking the "constructor" property, allowing attackers to set constructor.prototype. Although the assignment throws an error by default, if an application catches this error, the prototype pollution still occurs and injected code may execute. This is classified as CWE-1321 and is related to but distinct from CVE-2021-23433. The attack vector is network-based and requires no privileges or user interaction, but exploitability depends on error-handling behavior in consuming applications. The fix, released in version 3.11.2, ensures "constructor" is skipped during the merge operation, similar to existing __proto__ filtering.
Affected products
- Algolia algoliasearch-helper 2.0.0-rc1 through 3.11.1
Timeline
- 2023-01-09: disclosed
- 2025-09-27: advisory: Published to GitHub Security Advisory GHSA-529q-4j3p-7c5r and CVE-2025-3193
- 2025: patched: Fix released in version 3.11.2 via commit 776dff23c87b0902e554e02a8c2567d2580fe12a