Junglewise Threat Intelligence

CVE-2021-44906: minimist prototype pollution in argument parsing

CVE-2021-44906 · Severity: low · CVSS 3.1 · Published 2022-03-18

Technologies: Minimist.

Executive brief

minimist is a popular command-line argument parser library used in thousands of Node.js applications. A prototype pollution vulnerability allows attackers to inject malicious properties into JavaScript objects by crafting specially formatted command-line arguments, potentially leading to application crashes, unauthorized behavior, or code execution depending on how the parsed arguments are used downstream.

Technical details

The vulnerability is a prototype pollution flaw in the setKey() function (lines 69–95 of index.js) that fails to properly validate object keys when parsing command-line arguments. An attacker can craft arguments containing object property paths like --__proto__.polluted=true or --constructor.prototype.polluted=true to inject properties into the JavaScript object prototype, affecting all objects in the application. The vulnerability requires network or local access to supply crafted arguments to an application using minimist, with no authentication required. Exploitation can lead to application denial of service or behavior manipulation. The vulnerability was patched in minimist 1.2.6 (released 2022-03-18) and 0.2.4; applications using affected versions prior to these releases should update immediately.

Affected products

  • minimist minimist 0.0.0–0.2.3, 1.0.0–1.2.5

Timeline

  • 2022-03-18: disclosed: Advisory published (GHSA-xvch-5gv4-984h)
  • 2022-03-18: patched: minimist 1.2.6 and 0.2.4 released with fixes

References