Executive brief
gedi is a JavaScript library providing an evented data API. The library contains a prototype pollution vulnerability in its set function that allows attackers to inject arbitrary properties into the base JavaScript Object prototype, potentially leading to remote code execution, denial of service, or privilege escalation in applications using this library.
Technical details
The vulnerability is a prototype pollution flaw (CWE-1321) in the gedi library's set function that allows property definition by path without proper validation. An attacker can exploit this by passing a specially crafted path like "[__proto__/polluted]" to inject properties into Object.prototype. The attack requires only network access with no authentication; the vulnerability affects all versions up to and including 1.6.3. Exploitation can result in denial of service, property injection for privilege escalation, or remote code execution depending on how the affected application uses polluted properties. No patched version is available; the advisory recommends using alternative libraries or implementing mitigations such as Object.freeze() or schema validation.
Affected products
- gedi gedi up to and including 1.6.3
Timeline
- 2020-08-17: disclosed: Vulnerability disclosed to Snyk
- 2020-09-01: advisory: NVD published
- 2021-05-06: advisory: GHSA advisory published