Junglewise Threat Intelligence

CVE-2023-26139: underscore-keypath prototype pollution in setProperty

CVE-2023-26139 · Severity: low · CVSS 3.1 · Published 2023-08-01

Vendors: npm.

Executive brief

underscore-keypath is a JavaScript library that provides convenient access to object properties using key paths. A prototype pollution vulnerability in the setProperty() function allows attackers to modify JavaScript object prototypes by passing specially crafted property names like "__proto__", potentially affecting all objects in an application and leading to unexpected behavior or denial of service.

Technical details

The vulnerability is a prototype pollution flaw (CWE-1321) in the setValueForKeyPath() and setProperty() functions. The root cause is improper input sanitization: the name argument passed to setProperty() is not validated to prevent reserved keywords like "__proto__", "constructor", or "prototype". An attacker can exploit this via a network vector (e.g., via a web application using this library) by providing a malicious key path such as "__proto__.prop" or an array like ["__proto__", "prop"]. This allows direct assignment to the prototype object (obj[name] = value), polluting the base Object.prototype and affecting all subsequent object instantiation and property access. Affected versions are 0.0.11 through 0.9.3; a patch should implement strict input validation to block reserved prototype-related keys.

Affected products

  • underscore-keypath underscore-keypath 0.0.11 through 0.9.3

Timeline

  • 2023-08-01: disclosed
  • 2023-08-01: advisory

References