Junglewise Threat Intelligence

CVE-2022-37623: thlorenz browserify-shim prototype pollution in resolve-shims

CVE-2022-37623 · Severity: low · CVSS 3.1 · Published 2022-10-31

Technologies: browserify-shim (npm). Vendors: npm.

Executive brief

browserify-shim is a Node.js build tool that allows legacy CommonJS modules to be used in browser bundles. A prototype pollution vulnerability in the shimPath variable processing allows attackers to inject malicious properties into JavaScript objects, potentially corrupting application logic, escalating privileges, or enabling remote code execution in build pipelines.

Technical details

The vulnerability is a prototype pollution flaw in the resolveShims function within resolve-shims.js of browserify-shim version 3.8.15 and earlier. The vulnerability stems from unsafe manipulation of the shimPath variable, which allows an attacker to pollute the Object prototype by injecting properties through specially crafted input. No authentication or user interaction is required; a build process that processes untrusted or attacker-controlled configuration files can trigger the exploit. An attacker can modify prototype chain behavior to affect all objects in the JavaScript runtime, potentially leading to code execution or logic bypass. The vulnerability has been patched in version 3.8.16 and later.

Affected products

  • thlorenz browserify-shim 3.8.15 and earlier

Timeline

  • 2022-10-31: disclosed: Vulnerability published (GHSA-cfgr-75jx-h88g)
  • 2022-10-31: patched: Fix released in version 3.8.16

References

Related threats