Junglewise Threat Intelligence

CVE-2021-23397: @ianwalter/merge prototype pollution in merge function

CVE-2021-23397 · Severity: low · CVSS 3.1 · Published 2022-07-26

Vendors: npm.

Executive brief

@ianwalter/merge is a JavaScript library for recursively merging objects. A prototype pollution vulnerability in its merge function allows attackers to inject properties into the JavaScript Object prototype, potentially causing application crashes, tampering with security logic, or enabling remote code execution depending on how the application uses the polluted properties.

Technical details

The vulnerability is a prototype pollution flaw (CWE-1321) in the merge function that fails to properly sanitize the __proto__, constructor, or prototype properties when recursively merging source objects into targets. An attacker can craft a malicious JSON payload with a __proto__ property and pass it through the merge function to pollute Object.prototype, affecting all JavaScript objects created after the attack. This can lead to denial of service (triggering exceptions on built-in methods), property injection attacks (e.g., escalating privileges by setting isAdmin=true), or remote code execution if the application evaluates polluted prototype properties. All versions up to and including 9.0.1 are vulnerable, and the maintainer has marked the library as deprecated, recommending @generates/merger as an alternative with no known fixed version available for @ianwalter/merge itself.

Affected products

  • @ianwalter/merge 0 through 9.0.1 (all versions affected)

Timeline

  • 2021-06-17: disclosed
  • 2022-07-26: advisory

References