Executive brief
ts-fns is a TypeScript utility library used by developers to perform common functions. A prototype pollution vulnerability in its assign function allows attackers to inject malicious properties into the global object prototype, potentially causing application crashes, unexpected behavior, or bypassing security checks that rely on object integrity.
Technical details
The vulnerability is a prototype pollution flaw (CWE-1321) in the assign function of ts-fns, affecting versions prior to 13.0.7. It stems from insufficient validation of user-supplied property keys, allowing attackers to inject arbitrary properties (such as via __proto__) into Object.prototype. The vulnerability requires no authentication and can be triggered remotely by passing malicious key values to the assign function. Successful exploitation can lead to denial of service, unexpected code execution behaviors, or bypass of security-critical logic dependent on prototype integrity. The advisory notes the vulnerability remains unaddressed in the latest available version.
Affected products
- ts-fns prior to 13.0.7
Timeline
- 2025-08-06: disclosed: Issue opened on GitHub
- 2025-09-24: advisory: GHSA-g7wq-wggw-vmhg and CVE-2025-57351 published