Repository navigation
v0.4.1 - Security: patch axios prototype pollution
Security patch
Bumps axios from 1.15.1 → 1.16.0 to close two publicly disclosed prototype-pollution advisories that affect users on v0.4.0 (and v0.4.0-beta1 / v0.4.0-beta2):
- GHSA-q8qp-cvcw-x6jj — Prototype pollution in HTTP adapter → credential injection / request hijacking (CVSS 7.4, high)
- GHSA-3w6x-2g7m-8v23 — Prototype pollution in
parseReviver→ invisible JSON response tampering (CVSS 6.5, moderate)
The SDK uses axios for every RPC/REST call to FirmaChain and signs transactions based on parsed responses; tampered responses could mislead the signing flow.
Action required: users on 0.4.0 / 0.4.0-beta* should upgrade.
Install
npm install @firmachain/firma-jsFull Changelog: v0.4.0...v0.4.1