Executive brief
The field library is a JavaScript utility for getting and setting nested object properties. A prototype pollution vulnerability allows attackers to inject arbitrary properties into JavaScript object prototypes, potentially leading to denial of service or remote code execution in applications that use this library.
Technical details
This is a prototype pollution vulnerability (CWE-1321, CWE-915) in the field library's set() function, which recursively traverses and modifies nested object properties without proper validation of property names. An attacker can craft malicious field paths (e.g., "__proto__" or "constructor.prototype") to pollute the Object prototype chain, affecting all objects in the application. The vulnerability is reachable from network if the application accepts user-controlled input and passes it to field.set(). An attacker can achieve denial of service by breaking object functionality or potentially remote code execution if prototype pollution can be chained with other gadgets in the application's dependency chain.
Affected products
- jprichardson field 0.0.1 through 1.0.1
Timeline
- 2020-11-12: disclosed
- 2021-12-10: advisory