Junglewise Threat Intelligence

CVE-2023-26135: flatnest prototype pollution in nest function

CVE-2023-26135 · Severity: low · CVSS 3.1 · Published 2023-06-30

Vendors: npm.

Executive brief

flatnest is a JavaScript library for nesting and flattening object structures. A prototype pollution vulnerability in the nest() function allows attackers to inject malicious properties into the global Object prototype, potentially corrupting all objects in an application and leading to unexpected behavior, data leaks, or denial of service.

Technical details

The vulnerability is a prototype pollution flaw (CWE-1321) in the nest() function within nest.js. When processing nested object keys, the code unsafely creates parent objects without validating key names, allowing an attacker to pass keys like "__proto__.polluted" or "constructor.prototype.polluted" to modify the Object.prototype. The attack vector is network-accessible if the library is used to process untrusted input (e.g., JSON from an API or user-submitted data). No authentication or user interaction is required. Successful exploitation allows arbitrary property injection into the prototype chain, affecting all downstream objects. A fix was committed to the repository on 2023-06-30.

Affected products

  • node-flatnest flatnest ≤1.0.0

Timeline

  • 2022-12-28: disclosed: Issue opened on GitHub
  • 2023-06-30: advisory: GHSA-7px2-3c2p-q4v4 published
  • 2023-06-30: patched: Fix committed to repository

References