Executive brief
node-opcua-alarm-condition is a Node.js library that implements OPC UA alarm and condition functionality for industrial IoT systems. A prototype pollution vulnerability in the fieldsToJson function allows an attacker to send a crafted payload over the network, causing the application to crash or become unresponsive, disrupting industrial operations and system availability.
Technical details
The vulnerability is a prototype pollution flaw (CWE-1321) in the fieldsToJson function of node-opcua-alarm-condition that allows attackers to inject malicious properties into JavaScript objects. The vulnerability is triggered by supplying a crafted payload and requires only network connectivity with no authentication or user interaction needed. An attacker can exploit this to cause a Denial of Service (DoS) by crashing or degrading the application performance. The vulnerability affects all versions up to and including 2.134.0; it has been patched in version 2.137.0 and later.
Affected products
- node-opcua node-opcua-alarm-condition 0 through 2.136.x
Timeline
- 2025-02-05: disclosed: CVE-2024-57086 published
- 2025-02-06: advisory: GHSA-gvwq-6fmx-28xm advisory published
- 2025-02-06: patched: Fixed in version 2.137.0
- 2025-04-10: other: GitHub advisory reviewed and confirmed fix verified by community