data-fair-app
Audited by Socket on Oct 3, 2026
1 alert found:
AnomalyNo clear indicators of overt malware (no exec/eval, no external network requests, no credentials or persistence). However, the module has a high-impact security weakness: it accepts untrusted postMessage events without validating event.origin/event.source and uses an attacker-controlled dot-path writer (setByPath) to mutate nested configuration. This combination can enable configuration tampering and potentially prototype/structure pollution, which may lead to broader downstream security issues depending on how other parts of the app consume the provided config. Hardening should focus on strict postMessage origin/source verification, payload schema validation/whitelisting, and blocking dangerous path segments in setByPath.