CVE-2024-30564 is a critical prototype-pollution advisory for the @andrei-tatar/nora-firebase-common npm package [S1][S2]. Public advisory data identifies affected versions from 1.0.41 through 1.12.2, with 1.12.3 listed as the patched version [S2].
Impact
Prototype pollution happens when object update or merge logic allows untrusted keys to alter inherited object behavior [S1]. In affected @andrei-tatar/nora-firebase-common releases, the risk is tied to state-update handling that did not block prototype-chain keys before the upstream fix [S2][S3]. Depending on how an application passes state objects into the package, this can create denial-of-service, authorization, or code-execution risk, but those runtime effects depend on the deployed call path and available gadgets.
Covered by FixVibe
FixVibe's GitHub repo scans flag npm manifests or lockfiles that resolve @andrei-tatar/nora-firebase-common in the affected range, with the file, version, advisory IDs and fixed version.
Remediation
Upgrade @andrei-tatar/nora-firebase-common to 1.12.3 or later, regenerate the active npm, pnpm, or Yarn lockfile, rebuild the deployed application artifact, and rerun the FixVibe repo scan [S2][S3]. Review any code path that passes user-controlled state objects into update helpers and keep schema validation or prototype-key filtering in place for adjacent merge logic.
