Executive brief
CyberChef, a popular web-based tool for data analysis and encryption, contains a vulnerability in its 'Series Chart' feature. An attacker can provide a specially crafted CSV file that, when processed, allows them to execute malicious code within the user's browser. This could lead to the theft of sensitive data being processed in the tool or unauthorized actions performed on behalf of the user.
Technical details
A prototype pollution vulnerability exists in CyberChef's 'Series Chart' operation prior to version 11.2.0. The root cause is the operation's CSV parser accepting the '__proto__' key, which allows an attacker to modify the properties of the base JavaScript Object prototype. This can be chained with other operations, such as 'Parse UDP', which uses the 'objToTable' function in 'src/core/lib/Protocol.mjs' to render data in HTML tables without proper escaping. By polluting the prototype, an attacker can inject malicious JavaScript into the HTML output, resulting in Cross-Site Scripting (XSS). Exploitation requires a user to load a malicious recipe or input data. The issue is fixed in version 11.2.0 by using 'Object.create(null)' for data structures.
Affected products
- GCHQ CyberChef < 11.2.0
Timeline
- 2026-06-05: disclosed: Vulnerability reported by researcher @hyuunnn
- 2026-06-17: patched: Fix merged and version 11.2.0 released
- 2026-07-08: advisory: NVD and GitHub Security Advisory published