Executive brief
property-expr is a JavaScript library for parsing and manipulating object properties. A prototype pollution vulnerability in the setter function allows attackers to inject malicious properties into JavaScript object prototypes, potentially compromising the integrity and behavior of applications that use this library.
Technical details
The vulnerability is a prototype pollution flaw (CWE-1321/CWE-915) in the setter function of property-expr versions before 2.0.3. An attacker can inject properties into Object.prototype by crafting malicious input strings (e.g., "__proto__", "constructor", or "prototype" in the property path), which are not properly sanitized. This attack does not require authentication and is network-accessible if the application processes untrusted input. Successful exploitation allows an attacker to modify the behavior of all JavaScript objects in the application, potentially leading to authentication bypass, arbitrary code execution, or denial of service. The vulnerability was fixed in version 2.0.3.
Affected products
- jquense property-expr before 2.0.3
Timeline
- 2021-05-06: disclosed: Advisory published as GHSA-6fw4-hr69-g3rv
- 2020-08-17: patched: Fix released in version 2.0.3
- 2020-08-18: other: NVD entry published for CVE-2020-7707