# Prototype pollution vulnerability in function DEFNODE

**URL:** <https://discourse.nodered.org/t/prototype-pollution-vulnerability-in-function-defnode/69596>\
**Category:** General\
**Created:** [26 October 2022 06:15 UTC](https://discourse.nodered.org/t/prototype-pollution-vulnerability-in-function-defnode/69596 "2022-10-26T06:15:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![suraj\_k](https://avatars.discourse-cdn.com/v4/letter/s/8e7dd6/32.png) [@suraj\_k](https://discourse.nodered.org/u/suraj_k)\
**Post date:** [26 October 2022 06:15 UTC](https://discourse.nodered.org/t/prototype-pollution-vulnerability-in-function-defnode/69596/1 "2022-10-26T06:15:10Z")

</div>

There is an issue in my node package "uglify-js": "3.16.3" Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS via the name variable in ast.js. You can see more on this link [here](https://nvd.nist.gov/vuln/detail/CVE-2022-37598)

---

<div class="post-metadata">

**Author:** ![zenofmud](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/zenofmud/32/316_2.png) [@zenofmud](https://discourse.nodered.org/u/zenofmud)\
**Post date:** [26 October 2022 09:57 UTC](https://discourse.nodered.org/t/prototype-pollution-vulnerability-in-function-defnode/69596/2 "2022-10-26T09:57:26Z")

</div>

How is this related to Node-RED?  
If it is connected to a NR node, it would help if you identified the node and provided information such as  
Node-RED version  
node.js version  
npm version  
platform you are running on  
OS you are using and version

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [26 October 2022 10:01 UTC](https://discourse.nodered.org/t/prototype-pollution-vulnerability-in-function-defnode/69596/3 "2022-10-26T10:01:33Z")

</div>

If this is related to the core of node-red, then reporting any possible security issue via the public forum is _not_ the way to do it.

Our responsible disclosure policy is documented here: [node-red/SECURITY.md at master · node-red/node-red · GitHub](https://github.com/node-red/node-red/blob/master/SECURITY.md)

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [26 October 2022 11:06 UTC](https://discourse.nodered.org/t/prototype-pollution-vulnerability-in-function-defnode/69596/4 "2022-10-26T11:06:15Z")

</div>

FWIW, uglify is not used / never loaded into memory.

The Dependency (should probably be removed) : [node-red/package.json at 946def022fa94e9998d5c6095838841a1c94e2da · node-red/node-red · GitHub](https://github.com/node-red/node-red/blob/946def022fa94e9998d5c6095838841a1c94e2da/packages/node_modules/%40node-red/registry/package.json#L24)

Only reference: [node-red/registry.js at 946def022fa94e9998d5c6095838841a1c94e2da · node-red/node-red · GitHub](https://github.com/node-red/node-red/blob/946def022fa94e9998d5c6095838841a1c94e2da/packages/node_modules/%40node-red/registry/lib/registry.js#L17)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [25 December 2022 11:07 UTC](https://discourse.nodered.org/t/prototype-pollution-vulnerability-in-function-defnode/69596/5 "2022-12-25T11:07:04Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
