Executive brief
web3-core-subscriptions is a JavaScript library that manages subscription connections for web3 applications. A prototype pollution vulnerability in the attachToObject function allows attackers to inject malicious properties into JavaScript's Object prototype via crafted payloads, potentially causing application crashes, data corruption, or enabling further attacks against dependent applications.
Technical details
The vulnerability is a prototype pollution issue (CWE-1321) in the attachToObject function of web3-core-subscriptions version 2.0.0-alpha.1 and earlier. The root cause is improper validation of property assignments that allows an attacker to modify Object.prototype. An attacker can supply a crafted payload without authentication or user interaction to inject properties, causing denial of service and potential code execution. The fix has been patched in later versions, with the commit d966042 addressing the issue by improving nullish value validation to prevent prototype pollution.
Affected products
- web3 web3-core-subscriptions <=2.0.0-alpha.1
Timeline
- 2025-09-24: disclosed
- 2022-06-07: patched: Fix committed to web3.js repository