Executive brief
The @adolph_dudu/ratio-swiper JavaScript library contains a prototype pollution vulnerability in its extendDefaults function. Attackers can inject malicious properties into the Object prototype by passing specially crafted arguments, potentially modifying the behavior of all objects in an application and leading to denial of service, code execution, or cross-site scripting attacks.
Technical details
The vulnerability is a prototype pollution flaw (CWE-1321) in the extendDefaults and parse functions within @adolph_dudu/ratio-swiper v0.0.2. An attacker can pass an argument containing the __proto__ property to these functions to pollute Object.prototype and inject arbitrary properties into all inheriting objects. The vulnerability requires no authentication or special preconditions—any code that calls the vulnerable functions with attacker-controlled input is susceptible. Successful exploitation can lead to remote code execution, denial of service, or cross-site scripting depending on gadget chains available in the application context. A patch or mitigation status is not documented in the advisory.
Affected products
- adolph_dudu ratio-swiper 0.0.2
Timeline
- 2024-07-01: disclosed