Junglewise Threat Intelligence

CVE-2020-7718: gammautils prototype pollution in deepSet and deepMerge

CVE-2020-7718 · Severity: low · CVSS 3.1 · Published 2021-05-06

Vendors: npm.

Executive brief

gammautils is a Node.js utility library used by developers for common programming tasks. A prototype pollution vulnerability in its deepSet and deepMerge functions allows attackers to inject arbitrary properties into JavaScript object prototypes, potentially leading to application crashes, property tampering, or unauthorized privilege escalation depending on how the affected code uses object properties.

Technical details

Prototype Pollution (CWE-1321) in gammautils versions up to 0.0.81 occurs in the deepSet and deepMerge functions, which lack proper validation when processing object properties. An attacker can craft input containing the __proto__ property (or related prototype-chain properties) to modify Object.prototype. The vulnerability is network-reachable if the application accepts untrusted input and passes it to these functions; no authentication is required. Successful exploitation can cause denial of service by corrupting inherited object properties, inject malicious property values that alter application logic, or enable privilege escalation if the codebase relies on prototype properties for authorization checks. No patched version exists; the package maintainer has not released a fix.

Affected products

  • gammautils gammautils all versions up to and including 0.0.81

Timeline

  • 2020-08-14: disclosed
  • 2020-09-01: advisory: NVD published
  • 2021-05-06: advisory: GHSA advisory published

References