Executive brief
JSON5 is a popular JavaScript library for parsing JSON-like syntax with extended features. The library's parse method fails to block the special __proto__ key, allowing attackers to inject malicious properties into parsed objects. This can lead to security bypass, privilege escalation, data exfiltration, or in extreme cases remote code execution if applications trust the parsed data for authorization decisions.
Technical details
The vulnerability is a prototype pollution flaw in the JSON5 parse() method that does not restrict keys named __proto__. When an attacker supplies specially crafted JSON5 input with a __proto__ key, the parser pollutes the prototype of the returned object rather than the global Object prototype. Attack vector is network-based with no authentication required; however, it requires the application to use parsed JSON5 data in privileged operations without proper filtering. An attacker can inject arbitrary properties that bypass security checks relying on Object.keys() enumeration. Patches are available in json5 v2.2.2+ and v1.0.2+.
Affected products
- json5 json5 2.0.0 through 2.2.1 (fixed in 2.2.2); versions before 1.0.2 (fixed in 1.0.2)
Timeline
- 2022-12-23: disclosed
- 2022-12-29: patched