Exploiting prototype pollution in Node without the filesystem
portswigger.net | research | #rce | #web-security | #prototype-pollution | #nodejs | #import-flag | #server-side-prototype-pollution
Summary
A new SSPP exploitation technique: Node's --import flag accepts data: URLs, so polluting NODE_OPTIONS runs arbitrary code without touching the filesystem; Node considers this out of scope.
- Published
- Collected
Skip to content