Prototype Pollution

Prototype Pollution: Manipulation of the JavaScript object prototype so that all objects inherit attacker-controlled values. The vulnerability is an injectionInjection AttackManipulates interpreters or applications via injected commands or data. at the language level, ranging from privilege escalation to code execution.

How it works and where it fits

In JavaScript all objects inherit from Object.prototype. If an application processes attacker-controlled keys recursively — typically in deepMerge, extend, or when parsing nested query parameters — and fails to filter __proto__, constructor, and prototype, the attacker writes straight into the prototype. Every object in the process then carries that property unless it defines its own. This fallback is exactly what makes the attack so effective.

Practical security relevance

The impact only materialises where the value is later read. If an authorization check reads a property the real object does not own, the poisoned prototype answers instead — and the attacker inherits the permission. If a component reads a file or command name from it, the result is remote code executionRemote Code ExecutionVulnerability or attack that allows code to be executed on a remote target.. Mitigation means blocking dangerous keys during merges, using Object.create(null) or Map for data containers, and basing permission checks strictly on own properties.

  • Injection AttackInjection AttackManipulates interpreters or applications via injected commands or data.: Manipulates interpreters or applications via injected commands or data.
  • Remote Code ExecutionRemote Code ExecutionVulnerability or attack that allows code to be executed on a remote target.: Vulnerability or attack that allows code to be executed on a remote target.
  • Input ValidationInput ValidationVerification of input data regarding format, length, type, value range, and validity.: Verification of input data regarding format, length, type, value range, and validity.
  • Application SecurityApplication SecurityProtects software against vulnerabilities during development, operation, and maintenance.: Protects software against vulnerabilities during development, operation, and maintenance.