Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected], [email protected]
Control: affects -1 + src:node-min-document
User: [email protected]
Usertags: pu

[ Reason ]
node-min-document is vulnerable to a prototype pollution
(CVE-2025-57352 #1116340).

[ Impact ]
Security issue

[ Tests ]
Test pass (patch is exactly the "unstable" change.

[ Risks ]
No risk, patch is trivial

[ Checklist ]
  [X] *all* changes are documented in the d/changelog
  [X] I reviewed all changes and I approve them
  [X] attach debdiff against the package in (old)stable
  [X] the issue is verified as fixed in unstable

[ Changes ]
Use Object.prototype.hasOwnProperty to avoid prototype pollution

Cheers,
Xavier
diff --git a/debian/changelog b/debian/changelog
index f680f36..6d0e46f 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,9 @@
+node-min-document (2.19.0+~cs2.20.2-2+deb13u1) trixie; urgency=medium
+
+  * Fix prototype polution (Closes: #1116340, CVE-2025-57352)
+
+ -- Xavier Guimard <[email protected]>  Sat, 26 Sep 2026 13:00:01 +0200
+
 node-min-document (2.19.0+~cs2.20.2-2) unstable; urgency=medium
 
   * Source-only upload
diff --git a/debian/patches/CVE-2025-57352.patch 
b/debian/patches/CVE-2025-57352.patch
new file mode 100644
index 0000000..2ed2637
--- /dev/null
+++ b/debian/patches/CVE-2025-57352.patch
@@ -0,0 +1,28 @@
+Description: Prevent prototype pollution in removeAttributeNS
+ Only delete attribute namespaces and attributes that are direct properties
+ of the attributes object, so that the __proto__ property cannot be used to
+ manipulate the prototype chain of JavaScript objects (CVE-2025-57352).
+Origin: upstream, https://github.com/Raynos/min-document/commit/fe32e8da
+Bug: https://github.com/Raynos/min-document/issues/54
+Bug-Debian: https://bugs.debian.org/1116340
+Forwarded: yes
+Last-Update: 2026-09-26
+
+--- a/dom-element.js
++++ b/dom-element.js
+@@ -128,9 +128,13 @@
+ 
+ DOMElement.prototype.removeAttributeNS =
+     function _Element_removeAttributeNS(namespace, name) {
++        // Prevent prototype pollution by checking if namespace is a direct 
property
++        if (!Object.prototype.hasOwnProperty.call(this._attributes, 
namespace)) {
++            return;
++        }
+         var attributes = this._attributes[namespace];
+-        if (attributes) {
+-            delete attributes[name]
++        if (attributes && Object.prototype.hasOwnProperty.call(attributes, 
name)) {
++            delete attributes[name];
+         }
+     }
+ 
diff --git a/debian/patches/series b/debian/patches/series
new file mode 100644
index 0000000..7c1ff7f
--- /dev/null
+++ b/debian/patches/series
@@ -0,0 +1 @@
+CVE-2025-57352.patch

Reply via email to