Executive brief
@cat5th/key-serializer is a JavaScript library for key-value serialization and manipulation. A prototype pollution vulnerability in its query, set, and related functions allows attackers to inject arbitrary properties into the Object prototype, potentially leading to denial of service, code execution, or application logic bypass depending on how the library is used in downstream applications.
Technical details
This is a prototype pollution vulnerability (CWE-1321) in the query, set, default.query, and default.set functions of @cat5th/key-serializer version 0.2.5 and earlier. The vulnerable code fails to sanitize user-controlled input and allows attackers to craft arguments containing the __proto__ property to pollute the Object.prototype. An attacker with the ability to call these functions with attacker-controlled arguments can modify the prototype chain of all objects in the application. The impact ranges from denial of service to remote code execution or cross-site scripting, depending on how the polluted properties are used by gadgets in the consuming application. No patch information has been publicly disclosed as of the advisory date.
Affected products
- harvey-woo @cat5th/key-serializer 0.2.5 and earlier
Timeline
- 2024-07-01: disclosed
- 2024-07-11: advisory