Junglewise Threat Intelligence

CVE-2023-38894: tree-kit prototype pollution in extend function

CVE-2023-38894 · Severity: low · CVSS 3.1 · Published 2023-08-17

Vendors: npm.

Executive brief

tree-kit is a JavaScript library providing tree manipulation utilities like object extension and masking. A prototype pollution flaw in its extend function allows attackers to corrupt the JavaScript object prototype chain and execute arbitrary code on systems using vulnerable versions. This could enable complete system compromise, unauthorized access to sensitive data, or injection of malicious logic into applications.

Technical details

tree-kit v0.7.4 and earlier contain a prototype pollution vulnerability (CWE-1321) in the extend function when invoked with the 'unflat' option enabled. Prototype pollution allows an attacker to inject properties into Object.prototype, affecting all object instances in the JavaScript runtime. The vulnerability is remotely exploitable with no authentication or user interaction required (CVSS vector: AV:N/AC:L/PR:N/UI:N). An unauthenticated remote attacker can craft malicious input that, when processed by the vulnerable extend function, pollutes the prototype chain and achieves arbitrary code execution. The fix was released in version 0.7.5 via commit 61bf10cf0dbddaeea3f198cfe7cb469f360d82bc on GitHub.

Affected products

  • cronvel tree-kit 0.7.4 and earlier

Timeline

  • 2023-08-16: disclosed: NVD publication date
  • 2023-08-17: advisory: GHSA published
  • 2023-08-17: patched: Fixed in version 0.7.5

References

Related threats