Executive brief
CSVTOJSON is a popular Node.js library for converting CSV files to JSON format, widely used in data processing pipelines. The vulnerability allows an attacker to inject malicious properties into JavaScript's base object prototype by uploading specially crafted CSV files, potentially causing application crashes, unexpected behavior, or bypassing security validation logic in systems that rely on unmodified object prototypes.
Technical details
CSVTOJSON contains a prototype pollution vulnerability (CWE-1321) in its parser_jsonarray component due to insufficient sanitization of nested header names during CSV parsing. When CSV headers contain prototype-chain-referencing patterns (e.g., __proto__, constructor.prototype), the library fails to validate and sanitize these property paths, allowing attackers to modify the base Object.prototype. The attack requires only that an attacker supply a malicious CSV file—no user interaction or authentication is needed. This can result in denial of service, unexpected application behavior, or potential bypass of downstream validation logic that depends on unmodified prototypes. The vulnerability was fixed in version 2.0.13; versions prior to 2.0.10 are confirmed affected.
Affected products
- Keyang csvtojson prior to 2.0.13
Timeline
- 2025-09-24: disclosed
- 2025-08-06: exploited: Vulnerability reported on GitHub on 2025-08-06
- 2025-09-24: patched: Fixed in version 2.0.13