High severity8.1NVD Advisory· Published Oct 17, 2023· Updated Jun 17, 2026
CVE-2023-45811
CVE-2023-45811
Description
Synchrony deobfuscator is a javascript cleaner & deobfuscator. A __proto__ pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitrary code execution. A __proto__ pollution vulnerability exists in the LiteralMap transformer allowing crafted input to modify properties in the Object prototype. A fix has been released in [email protected]. Users are advised to upgrade. Users unable to upgrade should launch node with the [--disable-proto=delete][disable-proto] or [--disable-proto=throw][disable-proto] flags
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
deobfuscatornpm | >= 2.0.1, < 2.4.4 | 2.4.4 |
Affected products
3- relative/synchronyv5Range: >= 2.0.1, < 2.4.4
Patches
Vulnerability mechanics
References
5- github.com/relative/synchrony/commit/b583126be94c4db7c5a478f1c5204bfb4162cf40nvdPatchWEB
- github.com/relative/synchrony/security/advisories/GHSA-jg82-xh3w-rhxxnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-jg82-xh3w-rhxxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-45811ghsaADVISORY
- github.com/relative/synchrony/security/advisories/src/transformers/literalmap.tsnvdBroken LinkWEB
News mentions
0No linked articles in our index yet.