Prototype Pollution Vulnerability in AlgoliaSearch Helper by Algolia
CVE-2025-3193
5.9MEDIUM
What is CVE-2025-3193?
Versions of the AlgoliaSearch Helper package from 2.0.0-rc1 and earlier than 3.11.2 are susceptible to a Prototype Pollution vulnerability within the _merge() function in merge.js. This flaw permits alterations to constructor.prototype, despite errors arising from these modifications. In rare instances where an error is caught, it may allow execution of injected code within user-supplied search parameters. It's noteworthy that in the default configuration of InstantSearch, user-modifiable searchParameters do not render this vulnerability exploitable.
Affected Version(s)
algoliasearch-helper 2.0.0-rc1 < 3.11.2