forwardemail / forwardemail/superagent

Polluting the Response object from a malicious content-type value

Open
#1,513 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
16.6k
Forks
1.3k
PR merge metrics
No merged PRs in 30d

Description

Hi!

I was looking at the source code (to build a flow libdef for the project), and found this line:
https://github.com/visionmedia/superagent/blob/db35cdcdb4c9ed388679034dfaceec8e0f41144c/src/response-base.js#L76

My concern is that I believe it can be abused by a rogue server to override existing properties on the object.

I'm not a security expert so I don't know what the implications are or could be.

What's your analysis?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.