Web Hack List

Collected research

Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js

Prototype pollution lets an attacker write properties onto Object.prototype, and Node.js's own standard library then reads them back as trusted input. Combining CodeQL taint analysis with dynamic property probing, the authors find 11 universal gadgets (shell, env, main, exports) and eight end-to-end RCEs in NPM CLI, Parse Server and Rocket.Chat.

Record

Researcher
Mikhail Shcherbakov, Musard Balliu and Cristian-Alexandru Staicu
Published by
arXiv.org
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mikhail Shcherbakov, Musard Balliu and Cristian-Alexandru Staicu, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .