# Summary `Store`/`LegacyStore` key internal lookup tables by the `type`, `id`, and relationship names from a JSON:API document. Because these were plain objects, a document with `type: "__proto__"` writes onto `Object.prototype`, polluting every object in the process. # Severity Suggested CVSS v3.1 `AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H` (8.1). The guaranteed impact is process-wide DoS / logic corruption; escalation to authorization bypass or RCE is dependent on gadgets in the consuming application. # Affected / Patched - Affected: `<= 4.2.0` (verified in `3.0.0` and `4.2.0`; all 3.x and 4.x). - Patched: `4.3.0`. # Details `type` is a string *value*, untouched by `JSON.parse`, and is used directly as an object key: ```js if (!models[type]) models[type] = {} // models["__proto__"] is Object.prototype → skipped if (!models[type][id]) models[type][id] = model // → Object.prototype[id] = model ``` The attacker controls the polluted key (`id`) and value (the model, populated from `attributes`). Pollution persists for the process lifetime. The malicious type can also arrive via an `included` resource referenced by a relationship, bypassing any `data.type` allow-list. `LegacyStore` is additionally reachable when a configured `types` mapping resolves to `"__proto__"`. # Proof of concept ```js const { Store } = require('yayson')() new Store().sync({ data: { type: '__proto__', id: 'polluted', attributes: { x: 1 } } }) console.log(({}).polluted) // { x: 1, id: 'polluted' } ← Object.prototype polluted ``` # Workarounds Reject documents whose `type` or relationship names are `__proto__`, `constructor`, or `prototype`, or run Node with `--disable-proto=throw`. # Fix Null-prototype lookup tables, rejection of `__proto__`/`constructor`/`prototype` as document-derived member names, `Object.keys()` iteration, and null-prototype normalization of caller-supplied caches.
Loading application…