VYPR
High severity8.1NVD Advisory· Published Oct 17, 2023· Updated Jun 17, 2026

CVE-2023-45811

CVE-2023-45811

Description

Synchrony deobfuscator is a javascript cleaner & deobfuscator. A __proto__ pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitrary code execution. A __proto__ pollution vulnerability exists in the LiteralMap transformer allowing crafted input to modify properties in the Object prototype. A fix has been released in [email protected]. Users are advised to upgrade. Users unable to upgrade should launch node with the [--disable-proto=delete][disable-proto] or [--disable-proto=throw][disable-proto] flags

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
deobfuscatornpm
>= 2.0.1, < 2.4.42.4.4

Affected products

3
  • cpe:2.3:a:relative:synchrony:*:*:*:*:*:node.js:*:*
    Range: >=2.0.1,<2.4.4
  • ghsa-coords
    Range: >= 2.0.1, < 2.4.4
  • relative/synchronyv5
    Range: >= 2.0.1, < 2.4.4

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.