Executive brief
fullPage.js is a popular JavaScript library for creating single-page websites with full-screen scrolling effects. The library exposes utility functions through a global API that can be misused to pollute the JavaScript prototype chain. An attacker can exploit this to inject malicious properties into objects, potentially corrupting the behavior of any JavaScript application that depends on those objects, leading to data theft or application malfunction.
Technical details
The vulnerability exists in the deepExtend utility function exposed via window.fp_utils, which fails to properly validate or filter object keys before merging properties. An attacker can craft input containing "__proto__" or "constructor.prototype" keys to pollute the prototype of all objects of a given type. The attack requires no authentication and is triggered by network-accessible JavaScript execution (e.g., if user-controlled data is passed to deepExtend). The impact depends on how dependent code uses the polluted properties; in severe cases, it can lead to authentication bypass, data exfiltration, or remote code execution. The vendor patched this in version 4.0.2.
Affected products
- Alvaro Trigo fullPage.js before 4.0.2
Timeline
- 2022-04-12: disclosed
- 2022-04-11: patched: Fix released in version 4.0.2