Junglewise Threat Intelligence

Commercial @commercial/subtext prototype pollution in multipart parsing

Severity: info · Published 2020-09-03

Technologies: @commercial/subtext (npm). Vendors: npm.

Executive brief

@commercial/subtext is a library used to parse incoming web request payloads. A vulnerability in how it handles multipart data allows an attacker to manipulate the internal structure of the application's data objects. This can lead to application crashes (denial of service) or the bypassing of security validation rules, potentially exposing private information or allowing unauthorized actions.

Technical details

A prototype pollution vulnerability exists in @commercial/subtext versions prior to 5.1.2. An attacker can construct a malicious multipart payload where one of the parts is used to set the prototype of the entire payload object. If the injected prototype contains specific data, it can be used to bypass validation logic that relies on object properties for access control or privacy. Alternatively, if the prototype is set to null, it can trigger unhandled exceptions and a denial-of-service state when the application attempts to access the request payload. The issue is fixed in version 5.1.2.

Affected products

  • Commercial @commercial/subtext < 5.1.2

Timeline

  • 2020-08-31: advisory: GitHub reviewed the advisory
  • 2020-09-03: disclosed: Advisory published via GHSA

References

Related threats