Executive brief
The @aedart/support package is a JavaScript utility library used to handle metadata decoration in application code. A prototype pollution vulnerability in its meta decorator could allow an attacker to modify object properties at the prototype level, potentially affecting sensitive metadata stored by decorated classes. This impact is limited because metadata can only be set when a class is explicitly decorated and must contain sensitive data to be exploitable.
Technical details
The vulnerability is a prototype pollution issue (CWE-1321) that occurs in the MetadataRecord when it is merged with a base class's metadata object via the meta decorator in @aedart/support. The root cause is improper control of object prototype attribute modifications during metadata merging. Exploitation requires that sensitive objects be stored as class metadata, and an attacker would need to control or influence the metadata being merged. The vulnerability was patched in version 0.6.1, fixing the unsafe object merging logic.
Affected products
- Aedart @aedart/support versions prior to 0.6.1
Timeline
- 2023-04-28: disclosed
- 2023-05-01: advisory
- 2023-05-01: patched: Version 0.6.1 released with fix