* fix: enforce ownPropertyOnly for inherited array indices
Route array index access (including negative indices, first/last, and the
first/last filters) through a shared readArrayElement helper so that
ownPropertyOnly hides prototype-inherited array indices, closing the
GHSA-fwxr-j5w2-587m bypass. The option's scope (property/index access
only, not filter transforms or iteration) is documented on the option.
Co-authored-by: Cursor <[email protected]>
* fix(filters): invoke Array.prototype methods on unsanitized array values
Call built-ins via Array.prototype.<m>.call(...) for values that come
from scope (join, compact, concat, slice, where/reject) so an overridden
instance method on unsanitized data cannot hijack filter behavior.
Methods on freshly-created arrays are left as-is.
Co-authored-by: Cursor <[email protected]>
* fix(filters): use String.prototype.slice for the string branch of slice
Route the non-array branch through String.prototype.slice.call so the
slice filter never dispatches through a possibly-overridden instance
method, matching the Array.prototype guard.
Co-authored-by: Cursor <[email protected]>
---------
Co-authored-by: Cursor <[email protected]>