GoogleChrome / GoogleChrome/workbox

Prototype pollution vulnerability in workbox-window WorkboxEvent

Open
#3,502 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
13k
Forks
880
Avg merge
2h 44m
Merged PRs (30d)
8

Description

Hi, we are a security team. We found a prototype pollution vulnerability in your project.

The issue affects `workbox-window` in `WorkboxEvent`.

The vulnerable behavior happens because `WorkboxEvent` can be invoked with a controlled `this` context and then uses `Object.assign(this, props)`. If `this` is bound to `Object.prototype`, global prototype pollution may occur.

## Impact

An attacker may be able to pollute the global prototype and affect other objects in the same runtime.

## Proof of concept

```js
const { WorkboxEvent } = require('workbox-window');

WorkboxEvent.call(Object.prototype, 'type', { polluted: true });

console.log(({}).polluted); // true
```

## Details

We confirmed the following case:

- sink: `./utils/WorkboxEvent.js:18`

The root cause is that attacker-controlled execution context and properties are passed into a direct object assignment targeting shared prototype objects.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.