Executive brief
@orpc/client is a JavaScript RPC client library used to communicate with remote servers. A prototype pollution vulnerability in its JSON deserializer allows unauthenticated attackers to inject malicious properties into the global JavaScript object prototype, affecting all objects on the server. This can lead to privilege escalation (bypassing authorization checks), service crashes, or remote code execution if gadgets are available.
Technical details
The vulnerability is a prototype pollution flaw in the StandardRPCJsonSerializer.deserialize() method, which processes attacker-controlled path segments from meta and maps arrays without validating dangerous keys like __proto__ and constructor. Attackers can inject arbitrary values via two vectors: the meta array (type-constrained values like Map/Set/Date) and the maps array (arbitrary strings via FormData fields cast as Blob). The deserialization occurs before Zod schema validation, so malicious payloads pollute the prototype even if requests are later rejected. The attack requires network access to an @orpc/client server endpoint. Impacts include privilege escalation through bypassed role checks, denial of service via overwritten built-in methods, and potential RCE if gadgets exist in application code or dependencies. The vulnerability is fixed in version 1.13.6.
Affected products
- oRPC @orpc/client <=1.13.5
Timeline
- 2026-03-02: disclosed: Published as GHSA-m272-9rp6-32mc
- 2026-03-02: patched: Fixed in version 1.13.6