Junglewise Threat Intelligence

CVE-2024-29650: @thi.ng/paths prototype pollution in mutIn

CVE-2024-29650 · Severity: low · CVSS 3.1 · Published 2024-03-25

Vendors: npm.

Executive brief

@thi.ng/paths is a popular JavaScript library for working with nested data structures. A prototype pollution vulnerability in versions 5.1.62 and earlier allows remote attackers to execute arbitrary code by manipulating the library's object merging functions, potentially leading to complete application compromise.

Technical details

This is a prototype pollution vulnerability (CWE-1321) in @thi.ng/paths, a JavaScript library for nested object manipulation. The vulnerability exists in the mutIn and mutInManyUnsafe functions, which fail to properly sanitize user input when merging objects. An attacker can exploit this by crafting malicious input containing __proto__ or constructor properties to pollute the Object prototype, enabling arbitrary code execution. The vulnerability affects all versions up to and including 5.1.62; a patch is available in version 5.1.63 and later. No authentication or user interaction is required to exploit this via network vectors.

Affected products

  • thi.ng @thi.ng/paths 5.1.62 and earlier

Timeline

  • 2024-03-25: disclosed: Vulnerability published to GitHub Security Advisory
  • 2024-03-25: patched: Fix released in version 5.1.63

References