Executive brief
grunt-util-property is a utility library used in Grunt build workflows to get and set object properties. A prototype pollution flaw allows an attacker to inject malicious properties into the JavaScript Object prototype through crafted __proto__ payloads, affecting all objects in the application. This could cause application crashes, privilege escalation through property spoofing, or code execution if the application evaluates polluted properties.
Technical details
The vulnerability is a prototype pollution issue in the property-setting function (CWE-1321), where user-controlled property paths are not validated before assignment. An attacker can supply a path like __proto__.toString to inject properties into Object.prototype. The vulnerable function accepts a target object and a property path; when the path contains __proto__, the assignment affects the base object prototype rather than the target object's own properties. This requires the attacker to be able to call the function with controlled inputs. Exploitation can lead to denial of service (by polluting standard methods like toString), property injection (forged security attributes), or remote code execution (if the application evaluates polluted properties). No patched version is available; all versions of grunt-util-property are affected.
Affected products
- grunt-util-property grunt-util-property all versions, including 0.0.2
Timeline
- 2020-04-12: disclosed: Vulnerability disclosed to Snyk
- 2022-07-17: advisory: NVD published advisory
- 2022-07-18: advisory: GitHub advisory GHSA-4hq8-jgr8-mw9j published