Junglewise Threat Intelligence

CVE-2024-24294: Blackprint @blackprint/engine prototype pollution via setDeepProperty

CVE-2024-24294 · Severity: low · CVSS 3.1 · Published 2024-05-20

Vendors: npm.

Executive brief

Blackprint @blackprint/engine is a JavaScript engine used for visual node-based programming and automation. A prototype pollution vulnerability in the _utils.setDeepProperty function allows attackers to inject malicious properties into JavaScript object prototypes, leading to arbitrary code execution and complete compromise of any application using the affected library versions.

Technical details

The vulnerability is a prototype pollution flaw (CWE-1321) in the setDeepProperty utility function of engine.min.js that fails to validate property paths before assignment. An attacker can exploit this via specially crafted input to the function to pollute the Object prototype or other core prototypes, achieving arbitrary code execution (CWE-94). The attack vector is network-based with no authentication or user interaction required. The vulnerable versions are 0.8.12 through 0.9.1; a fix was released in version 0.9.2. The root cause appears to be insufficient sanitization of path traversal in the deep property setter logic.

Affected products

  • Blackprint @blackprint/engine 0.8.12 through 0.9.1

Timeline

  • 2024-05-20: disclosed
  • 2024-05-20: patched: Fix released in version 0.9.2

References