Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38773
HistoryJan 05, 2023 - 7:22 a.m.

Prototype Pollution

2023-01-0507:22:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
128
json5 vulnerability
prototype pollution
internalize function
parse.js
restrict keys
attacker injection
crafted strings

0.006 Low

EPSS

Percentile

77.9%

json5 is vulnerable to prototype pollution. The vulnerability exists in the internalize function in parse.js due to not restricting keys named __proto__ which allows an attacker to inject specially crafted strings to pollute the prototype of the resulting object.