Executive brief
dottie is a JavaScript library used to manipulate and transform object properties via dot-notation paths, commonly used in web frameworks and ORMs like Sequelize. A flaw in versions 2.0.4–2.0.6 allows attackers to inject hidden properties into objects by bypassing the prototype pollution guard, potentially enabling authorization bypass (e.g., injecting admin privileges) and denial of service through method stripping.
Technical details
This vulnerability is a prototype pollution bypass in the set() and transform() functions. The root cause is an incomplete fix for CVE-2023-26132: the guard only checks if the first path segment equals '__proto__', but attackers can bypass this by placing '__proto__' in a non-first position (e.g., 'a.__proto__.polluted'). When such paths are processed, the __proto__ setter is triggered mid-traversal, allowing property injection into an intermediate object's prototype chain rather than its own properties. The injected properties are not own properties, making them invisible to hasOwnProperty() and Object.keys() while still accessible via normal property access. Attack requires only network access to an application using dottie to process untrusted input. Fix is available in version 2.0.7.
Affected products
- dottie.js dottie 2.0.4 through 2.0.6
Timeline
- 2026-02-26: disclosed
- 2026-02-26: patched: Fix released in version 2.0.7