Junglewise Threat Intelligence

CVE-2022-37258: steal prototype pollution in npm-convert.js

CVE-2022-37258 · Severity: low · CVSS 3.1 · Published 2022-09-17

Technologies: steal (npm). Vendors: npm.

Executive brief

steal is an npm package used to manage module loading and dependencies in JavaScript applications. A prototype pollution vulnerability in the npm-convert.js component allows attackers to pollute object prototypes, potentially leading to code execution, data corruption, or application behavior manipulation without authentication or user interaction.

Technical details

A prototype pollution vulnerability exists in the convertLater function of npm-convert.js in the steal package (versions up to 2.3.0), triggered via improper handling of the packageName variable. The vulnerability is classified as CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes). The attack is network-reachable with no authentication required and no user interaction needed, allowing an attacker to inject malicious properties into JavaScript object prototypes. Successful exploitation can result in arbitrary code execution, integrity violations, and service disruption. Patches should be available in versions after 2.3.0.

Affected products

  • stealjs steal up to 2.3.0

Timeline

  • 2022-09-14: disclosed
  • 2022-09-16: advisory
  • 2022-09-17: other: Published on OSV

References

Related threats