Junglewise Threat Intelligence

CVE-2020-7637: class-transformer prototype pollution

CVE-2020-7637 · Severity: low · CVSS 3.1 · Published 2020-04-07

Vendors: npm.

Executive brief

class-transformer is a JavaScript library used to transform plain objects into typed class instances. A prototype pollution vulnerability allows attackers to manipulate core JavaScript object properties, which could lead to unexpected application behavior, logic bypass, or denial of service depending on how the transformed data is used downstream.

Technical details

The vulnerability is a prototype pollution flaw in the classToPlainFromExist function of class-transformer versions through 0.2.3. By crafting a payload with a __proto__ property, an attacker can inject or modify properties on Object.prototype, affecting all objects in the application. The attack is network-reachable and requires no authentication or user interaction—an attacker simply needs to provide a malicious object to be transformed. This can corrupt application logic, bypass security checks, or cause denial of service. The fix is available in version 0.3.1 and later.

Affected products

  • TypeStack class-transformer through 0.2.3

Timeline

  • 2020-04-07: disclosed
  • 2020-04-07: patched: Fixed in version 0.3.1

References