Remote property injection

Remote property injection

Description

Letting untrusted input select an object property can overwrite application state or security-related options. Effects on prototypes depend on the target object and assigned value.

Potential impact

  • Overwriting fields that control permissions or behavior may cause incorrect security decisions or data processing.
  • Depending on the object and value, assignments may alter prototype behavior or overwrite existing methods.
  • Later code using the modified fields may throw exceptions or bypass validation.

Remediation

  • Restrict writable properties to a fixed, server-managed allow-list appropriate for the target object.
  • Use Map for a separate key-value store that needs arbitrary keys, and keep it separate from application configuration.
  • Object.create(null) avoids inherited properties in dictionary objects. It does not authorize changes to sensitive application fields.
  • A consistent "$" key prefix avoids collisions with built-in property names. Apply the same convention when reading values.
  • Validate each value for its allowed property's purpose. Character filtering alone does not restrict which application fields can be changed.

Examples

Before

javascript
const express = require("express");
const app = express();
const settings = { theme: "light", locale: "ko", administrator: false };

app.get("/settings", (req, res) => {
  const key = req.query.key;
  // An attacker can also select settings such as administrator.
  settings[key] = req.query.value;
  res.send("updated");
});

After

javascript
const express = require("express");
const app = express();
const settings = { theme: "light", locale: "ko", administrator: false };
const ALLOWED_KEYS = ["theme", "locale"];

app.get("/settings", (req, res) => {
  const key = req.query.key;
  const value = req.query.value;
  if (typeof key !== "string" || !ALLOWED_KEYS.includes(key)) {
    return res.status(400).send("invalid key");
  }
  if ((key === "theme" && value !== "light" && value !== "dark") ||
      (key === "locale" && value !== "ko" && value !== "en")) {
    return res.status(400).send("invalid value for key");
  }
  settings[key] = value;
  res.send("updated");
});

Explanation:

  • Before: External input selects the field to modify, allowing changes to unintended settings. This example does not modify the shared prototype as a whole.
  • After: A server-owned allow-list restricts keys, and each selected field accepts only appropriate values. A request-supplied or subsequently altered allow-list is not a reliable safeguard.

OWASP classification

Improper modification of dynamically selected object attributes falls under CWE-915, which appears in the published OWASP Web Top 10 A08:2025 and A08:2021 lists. Classification alone does not establish widespread prototype pollution or successful follow-on attacks.

References