Description
Letting untrusted input select an object property can overwrite application state or security-related options. Effects on prototypes depend on the target object and assigned value.
Potential impact
- Overwriting fields that control permissions or behavior may cause incorrect security decisions or data processing.
- Depending on the object and value, assignments may alter prototype behavior or overwrite existing methods.
- Later code using the modified fields may throw exceptions or bypass validation.
Remediation
- Restrict writable properties to a fixed, server-managed allow-list appropriate for the target object.
- Use
Mapfor a separate key-value store that needs arbitrary keys, and keep it separate from application configuration. Object.create(null)avoids inherited properties in dictionary objects. It does not authorize changes to sensitive application fields.- A consistent
"$"key prefix avoids collisions with built-in property names. Apply the same convention when reading values. - Validate each value for its allowed property's purpose. Character filtering alone does not restrict which application fields can be changed.
Examples
Before
javascript
const express = require("express");
const app = express();
const settings = { theme: "light", locale: "ko", administrator: false };
app.get("/settings", (req, res) => {
const key = req.query.key;
// An attacker can also select settings such as administrator.
settings[key] = req.query.value;
res.send("updated");
});
After
javascript
const express = require("express");
const app = express();
const settings = { theme: "light", locale: "ko", administrator: false };
const ALLOWED_KEYS = ["theme", "locale"];
app.get("/settings", (req, res) => {
const key = req.query.key;
const value = req.query.value;
if (typeof key !== "string" || !ALLOWED_KEYS.includes(key)) {
return res.status(400).send("invalid key");
}
if ((key === "theme" && value !== "light" && value !== "dark") ||
(key === "locale" && value !== "ko" && value !== "en")) {
return res.status(400).send("invalid value for key");
}
settings[key] = value;
res.send("updated");
});
Explanation:
- Before: External input selects the field to modify, allowing changes to unintended settings. This example does not modify the shared prototype as a whole.
- After: A server-owned allow-list restricts keys, and each selected field accepts only appropriate values. A request-supplied or subsequently altered allow-list is not a reliable safeguard.
OWASP classification
Improper modification of dynamically selected object attributes falls under CWE-915, which appears in the published OWASP Web Top 10 A08:2025 and A08:2021 lists. Classification alone does not establish widespread prototype pollution or successful follow-on attacks.