Executive brief
dref is a JavaScript library used to manipulate object properties programmatically. A prototype pollution vulnerability in its core set function allows attackers to inject malicious properties into the global JavaScript object prototype, potentially causing application crashes or enabling further attacks depending on how the library is used within an application.
Technical details
This is a prototype pollution vulnerability (CWE-1321) in dref's lib.set function (version 0.1.2 and below). The vulnerability allows unauthenticated attackers to supply crafted payloads—such as "__proto__.pollutedKey"—that inject or modify properties in the Object.prototype chain. The attack requires network access and no authentication, and can be triggered by an application that processes untrusted input through dref's set function. An attacker can cause denial of service through prototype pollution, and depending on the application context, may escalate to arbitrary code execution if polluted properties reach sensitive Node.js APIs like exec or eval. Patches are available in versions after 0.1.2.
Affected products
- <UNKNOWN> dref 0.1.2 and earlier
Timeline
- 2025-09-25: disclosed
- other: CVE-2025-26278 assigned