Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Exploiting prototype pollution in Node without the filesystem

Summary

A new SSPP exploitation technique: Node's --import flag accepts data: URLs, so polluting NODE_OPTIONS runs arbitrary code without touching the filesystem; Node considers this out of scope.
Published
Collected

original ↗

Related coverage

back