Junglewise Threat Intelligence

CVE-2019-10750: deeply Prototype Pollution vulnerability

CVE-2019-10750 · Severity: low · CVSS 3.1 · Published 2019-08-27

Vendors: npm.

Executive brief

The deeply package is a Node.js library for manipulating complex data structures through deep merge and clone operations. Versions prior to 3.1.0 suffer from prototype pollution, allowing attackers to modify the Object prototype itself and inject or alter properties across all objects in an application. This could lead to unexpected behavior, data corruption, or denial of service.

Technical details

The vulnerability is a Prototype Pollution flaw (CWE-1321) in the assign-deep function within the deeply package. The function fails to validate which Object properties it updates, allowing attackers to inject properties via "__proto__" or similar payloads during a merge operation. The attack requires network access to an application using the vulnerable library and does not require authentication. An attacker can modify Object.prototype by crafting a malicious JSON payload (e.g., {"__proto__": {"a0": true}}) passed to the merge function, affecting all object instances. The vulnerability is fixed in version 3.1.0 and later.

Affected products

  • npm deeply <3.1.0

Timeline

  • 2019-06-20: disclosed
  • 2019-08-27: advisory
  • 2019: patched: Fixed in version 3.1.0

References