Executive brief
The flat-to-nested library, used to convert flat data structures into hierarchical trees, is vulnerable to prototype pollution. An attacker can provide specially crafted data records that modify the behavior of the underlying JavaScript environment. This can lead to application-wide logic errors, service outages, or potentially more severe security breaches depending on how the application uses the polluted data.
Technical details
The `convert()` method in `flat-to-nested` (specifically `FlatToNested.prototype.convert`) is vulnerable to prototype pollution (CWE-1321). The vulnerability arises because the library uses plain JavaScript objects (`{}`) as lookup tables for `id` and `parent` keys without sanitization. By providing a record with a `parent` value of `__proto__`, an attacker can cause the library to resolve the lookup to `Object.prototype`. Subsequent operations then write attacker-controlled data to the global prototype. This can be exploited remotely if the application processes untrusted input (e.g., from a database or API) through this library. The issue is fixed in version 1.1.2 by using prototype-less objects (`Object.create(null)`) for internal lookups.
Affected products
- joaonuno flat-to-nested <= 1.1.1
Timeline
- 2026-06-16: disclosed
- 2026-06-19: advisory: GHSA-hp36-v28f-w3r4 published
- 2026-06-19: patched: Version 1.1.2 released