Hacksplaining
FeaturesLessonsEnterpriseThe BookOWASP Top 10PCI Compliance
Sign Up
Log In
FeaturesLessonsEnterpriseThe BookOWASP Top 10PCI Compliance Sign Up Log In

Prototype Pollution

However, JavaScript objects can be instantiated from or have their state updated by JSON input very easily. If you manipulate the state of in-memory objects from untrusted input, you need to be very careful what properties on the JavaScript object can be manipulated.

Lessons
Glossary
Terms and Conditions
Privacy Policy

© 2026 Hacksplaining Inc. All rights reserved. Questions? Email us at support@hacksplaining.com