Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js
Mikhail Shcherbakov, Musard Balliu, Cristian-Alexandru Staicu
摘要
Prototype pollution is a dangerous vulnerability affecting prototype-based languages like JavaScript and the Node.js platform. It refers to the ability of an attacker to inject properties into an object's root prototype at runtime and subsequently trigger the execution of legitimate code gadgets that access these properties on the object's prototype, leading to attacks such as Denial of Service (DoS), privilege escalation, and Remote Code Execution (RCE). While there is anecdotal evidence that prototype pollution leads to RCE, current research does not tackle the challenge of gadget detection, thus only showing feasibility of DoS attacks, mainly against Node.js libraries. In this paper, we set out to study the problem in a holistic way, from the detection of prototype pollution to detection of gadgets, with the ambitious goal of finding end-to-end exploits beyond DoS, in full-fledged Node.js applications. We build the first multi-staged framework that uses multi-label static taint analysis to identify prototype pollution in Node.js libraries and applications, as well as a hybrid approach to detect universal gadgets, notably, by analyzing the Node.js source code. We implement our framework on top of GitHub's static analysis framework CodeQL to find 11 universal gadgets in core Node.js APIs, leading to code execution. Furthermore, we use our methodology in a study of 15 popular Node.js applications to identify prototype pollutions and gadgets. We manually exploit eight RCE vulnerabilities in three high-profile applications such as NPM CLI, Parse Server, and Rocket.Chat. Our results provide alarming evidence that prototype pollution in combination with powerful universal gadgets lead to RCE in Node.js.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper24
- DONAPI: Malicious NPM Packages Detector using Behavior Sequence Knowledge MappingCheng Huang, Nannan Wang, Ziyan Wang, Siqi Sun 等USENIX Security 2024 · 被引用 38 次
- SecBench.js: An Executable Security Benchmark Suite for Server-Side JavaScriptMasudul Hasan Masud Bhuiyan, Adithya Srinivas Parthasarathy, Nikos Vasilakis, Michael Pradel 等ICSE 2023 · 被引用 20 次
- Undefined-oriented Programming: Detecting and Chaining Prototype Pollution Gadgets in Node.js Template Engines for Malicious ConsequencesZhengyu Liu, Kecheng An, Yinzhi CaoS&P 2024 · 被引用 17 次
- Jack-in-the-box: An Empirical Study of JavaScript Bundling on the Web and its Security ImplicationsJeremy Rack, Cristian-Alexandru StaicuCCS 2023 · 被引用 11 次
- Unveiling the Invisible: Detection and Evaluation of Prototype Pollution Gadgets with Dynamic Taint AnalysisMikhail Shcherbakov, Paul Moosbrugger, Musard BalliuWWW 2024 · 被引用 8 次
它引用的顶会 Paper20
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web ServersCristian-Alexandru Staicu, Michael PradelUSENIX Security 2018 · 被引用 125 次
- SYNODE: Understanding and Automatically Preventing Injection Attacks on NODE.JSCristian-Alexandru Staicu, Michael Pradel, Benjamin LivshitsNDSS 2018 · 被引用 91 次
- BreakApp: Automated, Flexible Application CompartmentalizationNikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn 等NDSS 2018 · 被引用 66 次
- Finding and Preventing Bugs in JavaScript BindingsFraser Brown, Shravan Narayan, Riad S. Wahby, Dawson R. Engler 等S&P 2017 · 被引用 63 次
相关 Paper
- GHunter: Universal Prototype Pollution Gadgets in JavaScript RuntimesEric Cornelissen, Mikhail Shcherbakov, Musard BalliuUSENIX Security 2024 · 被引用 5 次
- Detecting Node.js prototype pollution vulnerabilities via object lookup analysisSong Li, Mingqing Kang, Jianwei Hou, Yinzhi CaoFSE 2021 · 被引用 49 次
- Bullseye: Detecting Prototype Pollution in NPM Packages with Proof of Concept ExploitsTariq Houis, Shaoqi Jiang, Mohammad Mannan, Amr YoussefNDSS 2026 · 被引用 2 次
- Follow My Flow: Unveiling Client-Side Prototype Pollution Gadgets from One Million Real-World WebsitesZifeng Kang, Muxi Lyu, Zhengyu Liu, Jianjia Yu 等S&P 2025
- Automated Exploit Generation for Node.js PackagesFilipe Marques, Mafalda Ferreira, André Nascimento, Miguel E. Coimbra 等PLDI 2025 · 被引用 5 次
