Executive brief
mpregular is a lightweight JavaScript framework for building web applications. A flaw in its event handler function allows attackers to inject malicious properties into core JavaScript objects, which can degrade performance, break application functionality, or cause complete service outages.
Technical details
A prototype pollution vulnerability exists in the mp.addEventHandler function of mpregular version 0.2.0 and earlier. The vulnerability occurs because user-supplied input is not properly validated before being assigned to Object.prototype properties. An attacker can supply a crafted payload to inject arbitrary properties into the prototype chain, affecting all objects in the application. The attack requires only network access and no authentication; successful exploitation results in denial of service through application malfunction or resource exhaustion. A fix is available in versions after 0.2.0.
Affected products
- mpregular mpregular 0.2.0 and earlier
Timeline
- 2025-09-24: disclosed
- 2025-09-24: advisory: GHSA-xx4g-r65p-3qf2 published