@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty
The _copyProps function in lib/src/object/copy.ts uses for...in to iterate over source object properties without an Object.hasOwnProperty check, and does not filter dangerous keys (proto, constructor, prototype). This allows an attacker to pollute the prototype chain of all objects in the application.
In _copyProps() (copy.ts lines 186-191), the code iterates all enumerable properties including inherited ones and dangerous keys like proto. Any object with a proto key (e.g., from untrusted JSON input) will overwrite the target's prototype.
const malicious = JSON.parse('{"__proto__": {"polluted": true}}');
objDeepCopy(malicious);
console.log({}.polluted); // true
Add objHasOwnProperty check and filter proto, constructor, prototype keys.
为什么是这个 VPI(可解释·实验性)
VPI 计算依据
| 影响度(严重程度等级估算值) | 80.00 |
| 利用信号(无额外利用信号) | ×1.00 |
| VPI | 80.00 |
VPI 公式 vpi-v1