Executive brief
Convict is a Node.js configuration management library used by applications to manage and validate application settings. A prototype pollution vulnerability in versions up to 6.2.4 allows attackers to inject arbitrary properties into JavaScript's Object.prototype by bypassing the validation logic. This could enable attackers to tamper with application behavior, bypass security checks, or crash services in any application that processes untrusted configuration input through Convict.
Technical details
The vulnerability is a prototype pollution flaw in Convict's input validation at line 564 of main.js, which uses String.prototype.startsWith() to block dangerous keys (e.g., "constructor.prototype"). An attacker can override String.prototype.startsWith to return false, bypassing the blocklist check and allowing keys like "constructor.prototype.polluted" to be set via config.set(). Since startsWith() is invoked on user-controlled strings, an attacker who can influence configuration input can pollute Object.prototype with arbitrary properties. The vulnerability affects all versions up to 6.2.4 and is patched in 6.2.5. Attack preconditions include the ability to pass untrusted input to convict.set(), which is locally exploitable if the application processes attacker-controlled config data. The impact ranges from authentication bypass to remote code execution if polluted properties are passed to code sinks like eval() or child_process().
Affected products
- Mozilla Convict <=6.2.4
Timeline
- 2026-03-26: disclosed: Advisory published
- 2026-03-26: patched: Fix released in version 6.2.5