Skip to content

Potential fix for code scanning alert no. 8: Prototype-polluting function - #14

Merged
ShadowDara merged 1 commit into
mainfrom
alert-autofix-8
Sep 13, 2026
Merged

ShadowDara merged 1 commit into
mainfrom
alert-autofix-8

Conversation

@ShadowDara

Copy link
Copy Markdown
Owner

Potential fix for https://github.com/ShadowDara/finder/security/code-scanning/8

General fix: harden the deep-assignment function so recursive traversal only proceeds through safe, own container properties on the destination object, and avoid writing through dangerous property names.

Best fix here (without changing intended behavior): keep the existing blocked-key check, and additionally ensure each intermediate segment is an own property before recursing; if absent, create it with a null-prototype object (Object.create(null)) to avoid inherited prototype behavior. If present but not a plain object, replace with Object.create(null). Before final assignment, also re-check the final key and ensure assignment target is object-like.

Edit only npm/site/src/configeditor/editor.tsx, inside setPath (lines around 118–130). No new imports are required.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…tion

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@ShadowDara
ShadowDara marked this pull request as ready for review September 13, 2026 20:45
@ShadowDara
ShadowDara merged commit 16481a2 into main Sep 13, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant