Executive brief
gh-pages is a Node.js library used to deploy static website content to GitHub Pages. A prototype pollution vulnerability in the library's utility functions allows attackers to modify JavaScript object prototypes, potentially leading to unauthorized modifications of application behavior, data theft, or denial of service. This could compromise any deployment pipeline or build process that uses the affected library.
Technical details
A prototype pollution vulnerability exists in the partial variable handling within util.js of gh-pages. The vulnerability is triggered through unsafe object manipulation that allows an attacker to inject malicious properties into JavaScript object prototypes. The attack is network-accessible without requiring authentication or user interaction (CVSS vector: AV:N/AC:L/PR:N/UI:N). An attacker can achieve arbitrary code execution or data manipulation by poisoning the shared prototype chain. The vulnerability affects all versions prior to 5.0.0, which includes the fix for this issue.
Affected products
- tschaub gh-pages before 5.0.0
Timeline
- 2022-10-12: disclosed: GHSA published
- 2022-10-10: other: Issue reported