GHSA-325j-mg25-8q58
yayson: Prototype pollution in Store/LegacyStore deserialization
Quick fix
GHSA-325j-mg25-8q58 — yayson: upgrade to the fixed version with the command below.
npm install yayson@4.3.0Details
# Summary `Store`/`LegacyStore` key internal lookup tables by the `type`, `id`, and relationship names from a JSON:API document. Because these were plain objects, a document with `type: "__proto__"` writes onto `Object.prototype`, polluting every object in the process.
# Severity Suggested CVSS v3.1 `AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H` (8.1). The guaranteed impact is process-wide DoS / logic corruption; escalation to authorization bypass or RCE is dependent on gadgets in the consuming application.
# Affected / Patched - Affected: `<= 4.2.0` (verified in `3.0.0` and `4.2.0`; all 3.x and 4.x). - Patched: `4.3.0`.
# Details `type` is a string *value*, untouched by `JSON.parse`, and is used directly as an object key: ```js if (!models[type]) models[type] = {} // models["__proto__"] is Object.prototype → skipped if (!models[type][id]) models[type][id] = model // → Object.prototype[id] = model ``` The attacker controls the polluted key (`id`) and value (the model, populated from `attributes`). Pollution persists for the process lifetime. The malicious type can also arrive via an `included` resource referenced by a relationship, bypassing any `data.type` allow-list. `LegacyStore` is additionally reachable when a configured `types` mapping resolves to `"__proto__"`.
# Proof of concept ```js const { Store } = require('yayson')() new Store().sync({ data: { type: '__proto__', id: 'polluted', attributes: { x: 1 } } }) console.log(({}).polluted) // { x: 1, id: 'polluted' } ← Object.prototype polluted ```
# Workarounds Reject documents whose `type` or relationship names are `__proto__`, `constructor`, or `prototype`, or run Node with `--disable-proto=throw`.
# Fix Null-prototype lookup tables, rejection of `__proto__`/`constructor`/`prototype` as document-derived member names, `Object.keys()` iteration, and null-prototype normalization of caller-supplied caches.
Are you affected?
Enter the version of the package you're using.