Executive brief
underscore-keypath is a JavaScript library that provides convenient access to object properties using key paths. A prototype pollution vulnerability in the setProperty() function allows attackers to modify JavaScript object prototypes by passing specially crafted property names like "__proto__", potentially affecting all objects in an application and leading to unexpected behavior or denial of service.
Technical details
The vulnerability is a prototype pollution flaw (CWE-1321) in the setValueForKeyPath() and setProperty() functions. The root cause is improper input sanitization: the name argument passed to setProperty() is not validated to prevent reserved keywords like "__proto__", "constructor", or "prototype". An attacker can exploit this via a network vector (e.g., via a web application using this library) by providing a malicious key path such as "__proto__.prop" or an array like ["__proto__", "prop"]. This allows direct assignment to the prototype object (obj[name] = value), polluting the base Object.prototype and affecting all subsequent object instantiation and property access. Affected versions are 0.0.11 through 0.9.3; a patch should implement strict input validation to block reserved prototype-related keys.
Affected products
- underscore-keypath underscore-keypath 0.0.11 through 0.9.3
Timeline
- 2023-08-01: disclosed
- 2023-08-01: advisory