Package: release.debian.org Severity: normal Tags: trixie X-Debbugs-Cc: [email protected], [email protected] Control: affects -1 + src:node-min-document User: [email protected] Usertags: pu
[ Reason ] node-min-document is vulnerable to a prototype pollution (CVE-2025-57352 #1116340). [ Impact ] Security issue [ Tests ] Test pass (patch is exactly the "unstable" change. [ Risks ] No risk, patch is trivial [ Checklist ] [X] *all* changes are documented in the d/changelog [X] I reviewed all changes and I approve them [X] attach debdiff against the package in (old)stable [X] the issue is verified as fixed in unstable [ Changes ] Use Object.prototype.hasOwnProperty to avoid prototype pollution Cheers, Xavier
diff --git a/debian/changelog b/debian/changelog index f680f36..6d0e46f 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,9 @@ +node-min-document (2.19.0+~cs2.20.2-2+deb13u1) trixie; urgency=medium + + * Fix prototype polution (Closes: #1116340, CVE-2025-57352) + + -- Xavier Guimard <[email protected]> Sat, 26 Sep 2026 13:00:01 +0200 + node-min-document (2.19.0+~cs2.20.2-2) unstable; urgency=medium * Source-only upload diff --git a/debian/patches/CVE-2025-57352.patch b/debian/patches/CVE-2025-57352.patch new file mode 100644 index 0000000..2ed2637 --- /dev/null +++ b/debian/patches/CVE-2025-57352.patch @@ -0,0 +1,28 @@ +Description: Prevent prototype pollution in removeAttributeNS + Only delete attribute namespaces and attributes that are direct properties + of the attributes object, so that the __proto__ property cannot be used to + manipulate the prototype chain of JavaScript objects (CVE-2025-57352). +Origin: upstream, https://github.com/Raynos/min-document/commit/fe32e8da +Bug: https://github.com/Raynos/min-document/issues/54 +Bug-Debian: https://bugs.debian.org/1116340 +Forwarded: yes +Last-Update: 2026-09-26 + +--- a/dom-element.js ++++ b/dom-element.js +@@ -128,9 +128,13 @@ + + DOMElement.prototype.removeAttributeNS = + function _Element_removeAttributeNS(namespace, name) { ++ // Prevent prototype pollution by checking if namespace is a direct property ++ if (!Object.prototype.hasOwnProperty.call(this._attributes, namespace)) { ++ return; ++ } + var attributes = this._attributes[namespace]; +- if (attributes) { +- delete attributes[name] ++ if (attributes && Object.prototype.hasOwnProperty.call(attributes, name)) { ++ delete attributes[name]; + } + } + diff --git a/debian/patches/series b/debian/patches/series new file mode 100644 index 0000000..7c1ff7f --- /dev/null +++ b/debian/patches/series @@ -0,0 +1 @@ +CVE-2025-57352.patch

