fix(uniforms): prototype pollution changing intended behavior#175
Open
bjormpro wants to merge 1 commit into
Open
fix(uniforms): prototype pollution changing intended behavior#175bjormpro wants to merge 1 commit into
bjormpro wants to merge 1 commit into
Conversation
fix prototype pollution safely without changing intended behavior, guard merge/clone operations against dangerous keys used to reach object prototypes (`__proto__`, `constructor`, `prototype`). The best targeted fix here is: 1. Add a small helper `isUnsafeKey(key: string): boolean`. 2. In `mergeInto`, skip entries with unsafe keys before recursion or assignment. 3. In `cloneRecord`, also skip unsafe keys so cloned objects cannot carry prototype-polluting keys. This keeps existing merge semantics for normal keys, preserves deep-copy behavior, and addresses both direct assignment and recursive merge paths.
|
@bjormpro is attempting to deploy a commit to the Vercel Labs Team on Vercel. A member of the Team first needs to authorize it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix prototype pollution safely without changing intended behavior, guard merge/clone operations against dangerous keys used to reach object prototypes (
__proto__,constructor,prototype). The best targeted fix here is:isUnsafeKey(key: string): boolean.mergeInto, skip entries with unsafe keys before recursion or assignment.cloneRecord, also skip unsafe keys so cloned objects cannot carry prototype-polluting keys.This keeps existing merge semantics for normal keys, preserves deep-copy behavior, and addresses both direct assignment and recursive merge paths.
References
lodash, jQuery, extend, just-extend, merge.recursive
CWE-78
CWE-79
CWE-94
CWE-400