Junglewise Threat Intelligence

CVE-2019-10806: vega-util prototype pollution in mergeConfig

CVE-2019-10806 · Severity: low · CVSS 3.1 · Published 2021-05-07

Vendors: npm.

Executive brief

vega-util is a utility library used by Vega, a popular data visualization framework. A flaw in the mergeConfig function allows attackers to inject properties into JavaScript's Object.prototype, potentially affecting all objects in an application and enabling malicious code execution or data manipulation across the entire system.

Technical details

The vulnerability is a prototype pollution flaw in vega-util's mergeConfig method (CWE-1321, CWE-20, CWE-915). The function fails to properly validate or sanitize configuration object properties, allowing an attacker with authentication/application access to craft malicious input that adds or modifies properties on Object.prototype. The vulnerability requires network access and authenticated/application-level interaction; it does not directly impact confidentiality but can lead to integrity violations and denial of service through pollution of shared prototype chains. The fix was released in version 1.13.1, which implements proper validation in the mergeConfig function to prevent prototype pollution.

Affected products

  • Vega vega-util prior to 1.13.1

Timeline

  • 2020-03-09: disclosed
  • 2021-05-07: patched: Fix released in vega-util 1.13.1

References