Executive brief
json-schema-ref-parser is a Node.js and browser library for parsing JSON Schema files with $ref pointers. A prototype pollution flaw in versions 11.0.0–11.1.0 allows remote attackers to inject malicious properties into all objects in an application by passing specially crafted JSON input. An attacker could exploit this to execute arbitrary code, crash the application, or modify application behavior in ways that lead to data theft or service disruption.
Technical details
The vulnerability is a Prototype Pollution issue (CWE-1321) in the unsafe merge() function within lib/options.ts. The function recursively copies properties from a source object to a target without filtering dangerous keys like __proto__, constructor, and prototype. When an attacker provides malicious JSON input containing __proto__ properties to functions like bundle(), parse(), resolve(), or dereference(), the merge function propagates these properties up the prototype chain, poisoning Object.prototype. This affects any new objects created after the attack. No user interaction or authentication is required; exploitation requires network access to feed crafted JSON to the vulnerable functions. The fix in version 11.2.0 filters out prototype pollution keys during the merge operation.
Affected products
- APIDevTools @apidevtools/json-schema-ref-parser 11.0.0 to 11.1.0
Timeline
- 2024-05-20: disclosed: Vulnerability published as GHSA-5f97-h2c2-826q
- 2024-05-20: patched: Fixed in version 11.2.0 with commit 8cad7f7