Executive brief
node-cube is a JavaScript utility library used for client-side execution in browser environments. A prototype pollution vulnerability allows attackers to inject malicious properties into core JavaScript objects without authentication, potentially causing denial of service, data corruption, or arbitrary code execution in applications using the library.
Technical details
The vulnerability is a prototype pollution issue (CWE-1321) in the setRequires method within the cycle_check module. The flaw stems from improper validation of user-supplied input during resource initialization, allowing attackers to manipulate prototype chains of native JavaScript objects such as Object.prototype. No authentication is required; the attack is network-reachable and requires no user interaction. Successful exploitation can result in denial of service, data integrity corruption, or arbitrary code execution in the Node.js runtime context. Affected versions include all releases up to and including 5.0.0-beta.19; no official patch has been released as of the advisory date.
Affected products
- node-cube node-cube prior to 5.0.0, including 5.0.0-beta.19
Timeline
- 2025-09-24: disclosed: Advisory published (GHSA-8v65-5fw5-23wj)
- 2025-08-06: other: Issue reported on GitHub