
Cloud Vulnerability DB
A community-led vulnerabilities database
A prototype pollution vulnerability was discovered in @thi.ng/paths module versions 5.1.62 and earlier, identified as CVE-2024-29650. The vulnerability allows remote attackers to execute arbitrary code via the mutIn and mutInManyUnsafe components (NVD, GitHub Gist).
The vulnerability exists in the mutIn and mutInManyUnsafe functions where properties of the source are assigned to the destination without proper verification of the property content and ownership. The issue occurs when paths.mutIn is invoked with a polluted proto property, which is passed as an argument from mutIn() in mut-in.js to defMutator() in mutator.js and then assigned to the destination. This allows manipulation of the prototype of an object, potentially affecting the behavior of all objects inheriting from the affected prototype (GitHub Gist). The vulnerability has been assigned a CVSS v3.1 base score of 9.8 CRITICAL (NVD).
A successful exploitation of this vulnerability could allow attackers to manipulate application logic, potentially leading to denial of service, remote code execution, or privilege escalation attacks. The vulnerability affects all objects sharing the same prototype, meaning a single successful attack could impact multiple objects across the application (GitHub Gist, Snyk Learn).
The vulnerability can be exploited by providing malicious input through the special properties proto or constructor.prototype of the built-in Object.prototype. A proof of concept demonstrates successful exploitation by using paths.mutIn or paths.mutInManyUnsafe with a polluted proto property (GitHub Gist).
Users should upgrade to version 5.1.63 or newer of the @thi.ng/paths package to address this vulnerability (GitHub Gist).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."