Skip to content

v0.4.1 - Security: patch axios prototype pollution

Choose a tag to compare

@thismars thismars released this 06 May 10:25
· 8 commits to main since this release
234a7a8

Security patch

Bumps axios from 1.15.1 → 1.16.0 to close two publicly disclosed prototype-pollution advisories that affect users on v0.4.0 (and v0.4.0-beta1 / v0.4.0-beta2):

  • GHSA-q8qp-cvcw-x6jj — Prototype pollution in HTTP adapter → credential injection / request hijacking (CVSS 7.4, high)
  • GHSA-3w6x-2g7m-8v23 — Prototype pollution in parseReviver → invisible JSON response tampering (CVSS 6.5, moderate)

The SDK uses axios for every RPC/REST call to FirmaChain and signs transactions based on parsed responses; tampered responses could mislead the signing flow.

Action required: users on 0.4.0 / 0.4.0-beta* should upgrade.

Install

npm install @firmachain/firma-js

Full Changelog: v0.4.0...v0.4.1