Algolia develops search-and-indexing libraries and helper utilities that integrate across client applications and websites, with disclosed vulnerabilities concentrated in the algoliasearch-helper product line. The durable signal centers on prototype pollution weaknesses, a class that arises from unsafe object-property manipulation in JavaScript contexts and can enable unintended behavior modification in consuming applications. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Algolia over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23433CRITICAL The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers | Nov 19, 2021 | 9.8 | 31 | NO | NO |
CVE-2025-3193HIGH Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.p | Sep 27, 2025 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Algolia.
Media articles that mention a CVE ID that affects a product developed by Algolia — matched by CVE ID, not by vendor name.