Repository navigation
fix(security): Prototype-pollution write via __proto__ route param in route-separation user loader - #7496
Open
failsafesecurity wants to merge 1 commit into
Conversation
… route-separation user loader
krzysdz
reviewed
Sep 29, 2026
Comment on lines
15
to
+17
| var id = req.params.id; | ||
| req.user = users[id]; | ||
| if (req.user) { | ||
| if (/^\d+$/.test(id) && Object.prototype.hasOwnProperty.call(users, id)) { | ||
| req.user = users[id]; |
Contributor
There was a problem hiding this comment.
Suggested change
| var id = req.params.id; | |
| req.user = users[id]; | |
| if (req.user) { | |
| if (/^\d+$/.test(id) && Object.prototype.hasOwnProperty.call(users, id)) { | |
| req.user = users[id]; | |
| var id = Number.parseInt(req.params.id); | |
| req.user = users[id]; | |
| if (req.user) { |
The suggestion is displayed incorrectly by GitHub, but simply wrapping req.params.id in Number.parseInt() is a simpler way to achieve the same thing.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security fix: Prototype-pollution write via proto route param in route-separation user loader
Severity: MEDIUM (CVSS 6.9)
CWE: CWE-1321
File:
examples/route-separation/user.jsWhat this fixes
In route-separation, user.load does
req.user = users[id](user.js:16) whereusersis an Array andidis the raw route param (index.js:41app.all('/user/:id{/:op}', user.load)). For id='proto' users['proto'] resolves to Array.prototype (truthy), so load() passes the existence check while req.user is actually Array.prototype. The subsequent PUT /user/proto/edit then executes req.user.name = body.user.name and req.user.email = body.user.email (user.js:44-45), writing attacker-controlled values onto Array.prototype. This is a single unauthenticated PUT that corrupts process-global state: every array and every object lacking its ownname/emailinherits the injected values. A GET /user/proto/view read-back renders the polluted values via Express's own array/params objects.The change
Validated the route param as a numeric index and checked it as an own property before indexing the users array, so prototype keys like proto/constructor/prototype cannot resolve to Array.prototype and get mutated by update().
Impact if unpatched
One unauthenticated PUT mutates Array.prototype for the whole Node process, poisoning every array/object in every concurrent request and any downstream library that reads
.name/.email(template rendering, logging, comparisons). This is process-global state corruption reachable cross-request — a primitive that is frequently a stepping stone to full RCE in real applications. Theconstructorvariant additionally crashes the request (500) exposing a stack trace.Prepared by OpenClaw BountyBot. Finding surfaced by Failsafe Nexus (Pandora) and the patch adversarially reviewed by GLM. Please review carefully — automated patches are a starting point, not a guarantee.