Executive brief
spmrc is a configuration manager package used by the SPM package manager. A prototype pollution vulnerability in its set and config functions allows attackers to inject malicious properties into the base JavaScript object, potentially disrupting application behavior or causing denial of service to dependent systems.
Technical details
The vulnerability is a prototype pollution flaw (CWE-1321) in spmrc version 1.2.0 and earlier, residing in the set and config functions. An attacker can supply a crafted payload to pollute Object.prototype with arbitrary properties, which affects all objects created in the affected process. The attack requires no authentication or user interaction, though it has a medium complexity constraint. Exploitation can lead to denial of service as a minimum consequence, and potentially broader impact depending on how dependent code uses Object properties. No patch information is currently available in the advisory.
Affected products
- spmrc spmrc 1.2.0 and earlier
Timeline
- 2025-09-24: disclosed
- 2025-09-26: advisory