Executive brief
browserify-shim is a Node.js build tool that allows legacy CommonJS modules to be used in browser bundles. A prototype pollution vulnerability in the shimPath variable processing allows attackers to inject malicious properties into JavaScript objects, potentially corrupting application logic, escalating privileges, or enabling remote code execution in build pipelines.
Technical details
The vulnerability is a prototype pollution flaw in the resolveShims function within resolve-shims.js of browserify-shim version 3.8.15 and earlier. The vulnerability stems from unsafe manipulation of the shimPath variable, which allows an attacker to pollute the Object prototype by injecting properties through specially crafted input. No authentication or user interaction is required; a build process that processes untrusted or attacker-controlled configuration files can trigger the exploit. An attacker can modify prototype chain behavior to affect all objects in the JavaScript runtime, potentially leading to code execution or logic bypass. The vulnerability has been patched in version 3.8.16 and later.
Affected products
- thlorenz browserify-shim 3.8.15 and earlier
Timeline
- 2022-10-31: disclosed: Vulnerability published (GHSA-cfgr-75jx-h88g)
- 2022-10-31: patched: Fix released in version 3.8.16