Collected research
Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js
Prototype pollution lets an attacker write properties onto Object.prototype, and Node.js's own standard library then reads them back as trusted input. Combining CodeQL taint analysis with dynamic property probing, the authors find 11 universal gadgets (shell, env, main, exports) and eight end-to-end RCEs in NPM CLI, Parse Server and Rocket.Chat.
Record
- Researcher
- Mikhail Shcherbakov, Musard Balliu and Cristian-Alexandru Staicu
- Published by
- arXiv.org
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Mikhail Shcherbakov, Musard Balliu and Cristian-Alexandru Staicu, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .