Executive brief
min-document is a JavaScript library that provides a minimal DOM implementation for server-side environments. A prototype pollution vulnerability in its removeAttributeNS method allows attackers to corrupt the JavaScript object prototype chain, potentially enabling arbitrary code execution or denial of service in applications that process untrusted input.
Technical details
This prototype pollution vulnerability (CWE-1321) exists in the removeAttributeNS method of min-document versions prior to 2.19.1. The root cause is insufficient validation of the namespace parameter when removing attributes, allowing attackers to pass the __proto__ property as input and modify the prototype chain of critical JavaScript objects. The vulnerability is reachable via any code path that calls removeAttributeNS with untrusted input; no authentication or elevated privileges are required. Successful exploitation can lead to property injection, denial of service, or arbitrary code execution depending on what properties are polluted. The fix is available in version 2.19.1.
Affected products
- Raynos min-document <2.19.1
Timeline
- 2025-09-24: disclosed
- 2025-09-24: patched: Version 2.19.1 fixes the vulnerability