{"id":"GHSA-3v7f-55p6-f55p","summary":"Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching","details":"### Impact\npicomatch is vulnerable to a **method injection vulnerability (CWE-1321)** affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression.\n\nThis leads to **incorrect glob matching behavior (integrity impact)**, where patterns may match unintended filenames. The issue does **not enable remote code execution**, but it can cause security-relevant logic errors in applications that rely on glob matching for filtering, validation, or access control.\n\nAll users of affected `picomatch` versions that process untrusted or user-controlled glob patterns are potentially impacted.\n\n### Patches\n\nThis issue is fixed in picomatch 4.0.4, 3.0.2 and 2.3.2.\n\nUsers should upgrade to one of these versions or later, depending on their supported release line.\n\n### Workarounds\n\nIf upgrading is not immediately possible, avoid passing untrusted glob patterns to picomatch.\n\nPossible mitigations include:\n- Sanitizing or rejecting untrusted glob patterns, especially those containing POSIX character classes like `[[:...:]]`.\n- Avoiding the use of POSIX bracket expressions if user input is involved.\n- Manually patching the library by modifying `POSIX_REGEX_SOURCE` to use a null prototype:\n\n  ```js\n  const POSIX_REGEX_SOURCE = {\n    __proto__: null,\n    alnum: 'a-zA-Z0-9',\n    alpha: 'a-zA-Z',\n    // ... rest unchanged\n  };\n  \n### Resources\n\n- fix for similar issue: https://github.com/micromatch/picomatch/pull/144\n- picomatch repository https://github.com/micromatch/picomatch","aliases":["CVE-2026-33672"],"modified":"2026-03-27T21:51:21.599209Z","published":"2026-03-25T21:13:39Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-03-25T21:13:39Z","nvd_published_at":"2026-03-26T22:16:30Z","cwe_ids":["CWE-1321"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/micromatch/picomatch/security/advisories/GHSA-3v7f-55p6-f55p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33672"},{"type":"WEB","url":"https://github.com/micromatch/picomatch/commit/4516eb521f13a46b2fe1a1d2c9ef6b20ddc0e903"},{"type":"PACKAGE","url":"https://github.com/micromatch/picomatch"}],"affected":[{"package":{"name":"picomatch","ecosystem":"npm","purl":"pkg:npm/picomatch"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.0.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-3v7f-55p6-f55p/GHSA-3v7f-55p6-f55p.json"}},{"package":{"name":"picomatch","ecosystem":"npm","purl":"pkg:npm/picomatch"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-3v7f-55p6-f55p/GHSA-3v7f-55p6-f55p.json"}},{"package":{"name":"picomatch","ecosystem":"npm","purl":"pkg:npm/picomatch"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.3.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-3v7f-55p6-f55p/GHSA-3v7f-55p6-f55p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}