Executive brief
csvjson is a JavaScript library that converts between CSV and JSON data formats. A prototype pollution vulnerability in the toCsv function allows attackers to inject malicious properties into the Object.prototype by supplying specially crafted input, leading to denial of service and potentially enabling further attacks on applications that use this library.
Technical details
A prototype pollution vulnerability (CWE-1321) exists in the toCsv function of csvjson through version 5.1.0. The vulnerability allows attackers to inject arbitrary properties on Object.prototype by providing a specially crafted payload. This occurs because the code does not properly validate or sanitize object property assignments. The attack requires network accessibility to an application using csvjson and can be exploited without authentication. Successful exploitation causes denial of service as a minimum consequence, with potential for greater impact depending on how the affected application uses the polluted prototype. Patches are available in versions after 5.1.0.
Affected products
- csvjson csvjson through 5.1.0
Timeline
- 2025-09-24: disclosed
- 2025-09-26: advisory