Prototype Pollution
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
If an attacker can access and modify prototype objects in JavaScript, you are in danger.
- Prevalence
- Common
- Exploitability
- Moderate
- Impact
- Harmful
What is prototype pollution?
Prototype pollution is an injection attack against JavaScript applications in which an attacker adds or changes properties on a prototype object, typically Object.prototype, through unsafe merging of untrusted input. Because objects inherit from their prototype, the change reaches every object in the application, and can lead to denial of service, bypassed access checks or remote code execution.
What you'll learn
- How JavaScript objects inherit properties from their prototypes
- How merging untrusted JSON lets an attacker modify Object.prototype
- How frozen objects, prototypeless objects and maps prevent pollution
Where this lesson counts
OWASP Top 10
Code and data are trusted without verifying integrity, from unsafe deserialization to unchecked object updates.
Learn more about A08This lesson includes
-
Prototype Pollution lab
See how JavaScript objects inherit from prototypes and how the __proto__ property lets code reach back and change them. The lab then shows how a file upload module that merged untrusted JSON into objects let attackers pollute every object on the server.
-
How to prevent Prototype Pollution
The prevention guide covers three approaches:
- Freeze Your Objects
- Use Prototypeless Object
- Use Maps Instead of Objects
-
Prototype Pollution quiz
Three questions. Passing marks the lesson complete.
Sources
- Prototype Pollution: A Deep-Dive NetSPI
- What is prototype pollution? PortSwigger
- CWE-1321 MITRE
Related lessons
Browse all 45 lessons
Remote Code Execution
If an attacker can smuggle code into your web-server process, you have a serious problem.
Mass Assignment
Automatically unpacking data from the HTTP request can sometimes be too easy.
DOM-based XSS
If you make use of URI fragments in your site, you need to ensure they cannot be abused to inject malicious JavaScript.
Denial of Service Attacks
Sometimes attackers don't need to hack your website, they just want to make it unavailable to others.