Executive brief
@alizeait/unflatto is a JavaScript library used to flatten nested data structures. A prototype pollution vulnerability in versions up to 1.0.2 allows attackers to inject malicious properties into JavaScript objects, enabling arbitrary code execution or service disruption in any application using the affected library.
Technical details
The vulnerability is a prototype pollution flaw (CWE-1321) in the unflatto method at /dist/index.js in @alizeait/unflatto versions up to 1.0.2. The vulnerability is remotely exploitable without authentication or user interaction required. By crafting a malicious input containing prototype chain keys (e.g., __proto__, constructor), an attacker can inject arbitrary properties into the Object prototype, leading to arbitrary code execution or denial of service. The issue has been patched in version 1.0.3.
Affected products
- alizeait unflatto <=1.0.2
Timeline
- 2025-04-01: disclosed
- 2025-04-01: patched: Fixed in version 1.0.3