Prototype Pollution Vulnerability in AlgoliaSearch Helper by Algolia
CVE-2025-3193

5.9MEDIUM

Key Information:

Vendor

Algolia

Vendor
CVE Published:
27 September 2025

What is CVE-2025-3193?

Versions of the AlgoliaSearch Helper package from 2.0.0-rc1 and earlier than 3.11.2 are susceptible to a Prototype Pollution vulnerability within the _merge() function in merge.js. This flaw permits alterations to constructor.prototype, despite errors arising from these modifications. In rare instances where an error is caught, it may allow execution of injected code within user-supplied search parameters. It's noteworthy that in the default configuration of InstantSearch, user-modifiable searchParameters do not render this vulnerability exploitable.

Affected Version(s)

algoliasearch-helper 2.0.0-rc1 < 3.11.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuhan Gao
Peng Zhou
.
CVE-2025-3193 : Prototype Pollution Vulnerability in AlgoliaSearch Helper by Algolia