Web Hack List

Collected research

Blitz.js Prototype Pollution Leads to Remote Code Execution

Traces unauthenticated RCE in Blitz.js from superjson's attacker-controlled referentialEqualities paths to Object.prototype pollution. The chain inserts a route into Next.js's pages manifest, loads the Blitz CLI wrapper, then pollutes child-process argv0, env, and shell so Node requires attacker-controlled code from /proc/self/cmdline.

Record

Researcher
Paul Gerste
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Paul Gerste, first published at the original source. Preserved copies are kept so the citation survives its host.