Junglewise Threat Intelligence

CVE-2020-7792: mout prototype pollution in deepFillIn and deepMixIn

CVE-2020-7792 · Severity: low · CVSS 3.1 · Published 2022-02-09

Vendors: npm.

Executive brief

mout is a popular JavaScript utility library providing helper functions for object manipulation. The deepFillIn and deepMixIn functions fail to validate keys during recursive property assignment, allowing attackers to pollute the Object prototype and corrupt application behavior across all objects, potentially causing denial of service or enabling privilege escalation.

Technical details

The vulnerability is a prototype pollution flaw (CWE-1321) in the deepFillIn and deepMixIn functions of the mout library. Both functions recursively merge or fill object properties but do not filter special keys like "__proto__", "constructor", or "prototype". An attacker can craft malicious objects with these keys to pollute the Object prototype, affecting all objects created after the attack. The attack requires network access if the library processes untrusted input (e.g., from API requests or user uploads), and is easily exploitable with no authentication required. The fix, released in version 1.2.3, adds validation in the set.js function to block prototype pollution keys.

Affected products

  • mout mout all versions before 1.2.3

Timeline

  • 2020-12-11: disclosed
  • 2021-04-08: patched: Security fix released in version 1.2.3
  • 2022-02-09: advisory

References

Related threats