Executive brief
steal is an npm package used for JavaScript module loading and bundling. A prototype pollution vulnerability in the npm-convert.js file allows attackers to pollute the Object prototype by crafting a malicious requestedVersion variable, potentially enabling code execution or application compromise without authentication.
Technical details
This is a prototype pollution vulnerability (CWE-1321) in the convertLater function within npm-convert.js. The vulnerable component fails to properly validate the requestedVersion variable before using it in object assignment operations. The attack requires no authentication and is network-reachable if the application processes user-controlled version inputs. Successful exploitation pollutes the Object prototype, which can lead to arbitrary code execution or denial of service depending on how the polluted properties are leveraged by the application. All versions up to 2.3.0 are affected.
Affected products
- stealjs steal up to 2.3.0
Timeline
- 2022-09-16: disclosed
- 2022-09-15: other: NVD published