Skip to content

[v16.x backport] lib: make primordials Promise methods safe

catch and finally methods on %Promise.prototype% looks up the then property of the instance, making it at risk of prototype pollution.

PR-URL: https://github.com/nodejs/node/pull/38650 Refs: https://tc39.es/ecma262/#sec-promise.prototype.catch Reviewed-By: James M Snell jasnell@gmail.com Reviewed-By: Matteo Collina matteo.collina@gmail.com

Merge request reports

Loading