Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x7j8-49r8-mr43

Опубликовано: 21 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.2

Описание

@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty

Summary

The _copyProps function in lib/src/object/copy.ts uses for...in to iterate over source object properties without an Object.hasOwnProperty check, and does not filter dangerous keys (proto, constructor, prototype). This allows an attacker to pollute the prototype chain of all objects in the application.

Details

In _copyProps() (copy.ts lines 186-191), the code iterates all enumerable properties including inherited ones and dangerous keys like proto. Any object with a proto key (e.g., from untrusted JSON input) will overwrite the target's prototype.

PoC

const malicious = JSON.parse('{"__proto__": {"polluted": true}}'); objDeepCopy(malicious); console.log({}.polluted); // true

Suggested Fix

Add objHasOwnProperty check and filter proto, constructor, prototype keys.

Пакеты

Наименование

@nevware21/ts-utils

npm
Затронутые версииВерсия исправления

<= 0.13.0

0.14.0

EPSS

Процентиль: 21%
0.00284
Низкий

7.2 High

CVSS4

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 7.5
redhat
17 дней назад

@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps function in lib/src/object/copy.ts uses for...in to iterate over source object properties without an Object.hasOwnProperty check, and does not filter dangerous keys (__proto__, constructor, prototype). This allows an attacker to pollute the prototype chain of all objects in the application. Version 0.14.0 patches the issue.

nvd
17 дней назад

@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps function in lib/src/object/copy.ts uses for...in to iterate over source object properties without an Object.hasOwnProperty check, and does not filter dangerous keys (__proto__, constructor, prototype). This allows an attacker to pollute the prototype chain of all objects in the application. Version 0.14.0 patches the issue.

EPSS

Процентиль: 21%
0.00284
Низкий

7.2 High

CVSS4

Дефекты

CWE-1321