Security Advisory: Prototype pollution of `Object.prototype.unsafe` silently disables serialize-javascript's documented automatic XSS escaping
还没有人认领这个 Issue。
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 72/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- javascript
- 领域
- security
调研方向
从 index.js 中第 123 行附近的选项默认值以及第 214 行和第 278 行附近的 unsafe 检查开始,然后将行为与 poc04_proto_pollution_xss.js 进行比较。验证继承的 Object.prototype.unsafe 无法禁用自动转义,同时显式传入的 unsafe 选项仍保持其文档所述行为。当 pollution 复现不再输出未转义的 HTML payload 时,即表示完成。
由索引模型根据 Issue 内容生成。
描述
Summary
| Attribute | Value |
|---|---|
| Vendor / Org | Yahoo |
| Product | serialize-javascript |
| Component | index.js — serialize() option reads |
| Affected Versions | >= 1.5.0, <= 7.1.1 (all releases exposing options.unsafe) |
| Severity | Medium |
| CVSS 3.1 Score | 6.9 |
| CVSS 3.1 Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N |
| CWE | CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes), chained to CWE-79 |
| Affected File | index.js:214, index.js:278 (option reads); index.js:123 (default) |
CVSS 3.1 Breakdown
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N — Score: 6.9 (Medium)
| Metric | Value | Justification (from the PoC) |
|---|---|---|
| Attack Vector (AV) | N | Payload arrives over the network as serialized data embedded into an HTML response. |
| Attack Complexity (AC) | H | Exploitation depends on a condition beyond the attacker's control: a separate in-process prototype-pollution gadget must already be reachable to set Object.prototype.unsafe. |
| Privileges Required (PR) | N | No authentication needed to submit the polluting payload or the XSS string. |
| User Interaction (UI) | R | A victim must load the page that embeds the unescaped output. |
| Scope (S) | C | The serializer's escaping component is subverted; impact lands in the victim's browser security context (a different authority). |
| Confidentiality (C) | H | Resulting XSS can read cookies/DOM/session in the victim origin. |
| Integrity (I) | L | Script can modify page content within the victim origin. |
| Availability (A) | N | No availability impact demonstrated. |
Description
Improper prototype-attribute control in the option handling of Yahoo serialize-javascript >= 1.5.0, <= 7.1.1 allows a remote attacker who can pollute Object.prototype to disable the library's automatic HTML/XSS escaping and inject script into consumer pages via a serialized string value.
serialize-javascript documents a security guarantee: "HTML characters and JavaScript line
terminators are escaped automatically" so output is safe as the content of a <script>
element. That escaping is gated by options.unsafe !== true, and options is a plain
object inheriting from Object.prototype. When any prototype-pollution gadget in the same
process sets Object.prototype.unsafe = true, every serialize() call — including calls
that pass no options at all — reads the inherited unsafe value as true and skips
escaping, emitting attacker-controlled markup verbatim.
Security consequence (so-what): a generic, data-only prototype-pollution primitive is
escalated into stored/reflected XSS in every browser that renders the serialized output,
because the library's own documented XSS defense is silently turned off.
Root Cause
options defaults to an ordinary object and the security-relevant flags are read as plain
(inherited) property accesses with no hasOwnProperty check:
options || (options = {}); // index.js:123
...
if (options && options.unsafe !== true) { // index.js:214
serializedFn = escapeFunctionBody(serializedFn);
}
...
if (options.unsafe !== true) { // index.js:278
str = str.replace(UNSAFE_CHARS_REGEXP, escapeUnsafeChars);
}
Because options.unsafe resolves through the prototype chain, a polluted
Object.prototype.unsafe is indistinguishable from an explicit {unsafe:true}. The
escaping at line 278/279 (the documented guarantee) is therefore skipped.
Reproduction Environment
| Item | Value |
|---|---|
| Runtime | Node.js v26.5.0 |
| serialize-javascript | 7.1.1 (installed from npm registry) |
| OS | macOS (darwin 25.6.0) |
| Build tool | npm |
Proof of Concept
POC Source Code
package.json
{
"name": "sjs-cve-poc",
"version": "1.0.0",
"private": true,
"dependencies": {
"serialize-javascript": "7.1.1"
}
}
poc04_proto_pollution_xss.js
// PoC #4 — a prototype-pollution gadget elsewhere in the process silently disables the
// README's documented automatic XSS escaping for EVERY serialize() call.
const serialize = require('serialize-javascript');
const payload = { bio: '</script><img src=x onerror=alert(1)>' };
// --- control baseline: default behavior escapes (documented guarantee) ---
console.log('BEFORE pollution:', serialize(payload));
// --- generic prototype-pollution gadget (data-only write reached via any PP sink) ---
Object.prototype.unsafe = true;
// --- same call, no options passed -> escaping is now silently OFF ---
const out = serialize(payload);
console.log('AFTER pollution:', out);
const escaped = !out.includes('</script>');
console.log('still escaped?', escaped, '=> XSS payload emitted verbatim:', !escaped);
delete Object.prototype.unsafe;
Execution Steps
mkdir poc && cd poc- Save the
package.jsonabove, thennpm install(pullsserialize-javascript@7.1.1). - Save the source above as
poc04_proto_pollution_xss.js. node poc04_proto_pollution_xss.js
Actual Execution Evidence
BEFORE pollution: {"bio":"\u003C\u002Fscript\u003E\u003Cimg src=x onerror=alert(1)\u003E"}
AFTER pollution: {"bio":"</script><img src=x onerror=alert(1)>"}
still escaped? false => XSS payload emitted verbatim: true
Analysis of Results
The control baseline (BEFORE) proves the library normally honours its documented
guarantee: <, >, / are emitted as \u003C, \u003E, \u002F. The only change
between the two calls is a single write to Object.prototype.unsafe; the serialize call
itself passes no options. Yet AFTER, the output contains a literal </script> closing
the inline script element followed by an executable <img onerror> — a working XSS payload.
Causality is therefore isolated to the inherited-property read at index.js:278.
Impact
Any application that (a) uses serialize-javascript to embed state into HTML relying on the
documented auto-escaping, and (b) has any prototype-pollution gadget reachable in the same
process, is exposed to XSS in every rendered page — even for serialize calls that never opt
into unsafe. This converts a data-only pollution write into browser-side code execution
in the consumer's origin.
Remediation
Recommended Fix
Read the security-relevant options as own properties and default to a null-prototype
object, so a polluted prototype cannot flip them:
options = (typeof options === 'object' && options) ? options : Object.create(null);
var unsafe = Object.prototype.hasOwnProperty.call(options, 'unsafe') && options.unsafe === true;
Use the local unsafe at lines 214/278. This restores the README guarantee ("HTML
characters and JavaScript line terminators are escaped automatically") for every caller
that does not explicitly pass {unsafe:true} as an own property — a maintainer-owned
change, not caller advice.
Workaround
Consumers can freeze/guard Object.prototype (e.g. run under a prototype-pollution
mitigation), or explicitly pass {unsafe:false} as an own property on every call.
References
- Affected source:
index.js:214,index.js:278,index.js:123in yahoo/serialize-javascript v7.1.1. - CWE-1321: https://cwe.mitre.org/data/definitions/1321.html
- CWE-79: https://cwe.mitre.org/data/definitions/79.html
- Distinct from prior serialize-javascript XSS advisories (GHSA-h9rv-jmmf-4pgx, GHSA-76p7-773f-r4q5) which concerned value escaping, not prototype-pollution of the
unsafegate.
- 主要语言
- JavaScript
- 星标
- 2.9k
- 派生
- 215
- 平均合并
- 1 天 12 小时
- 30 天内合并 PR
- 2
贡献指南
这个仓库没有索引到贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
yahoo/serialize-javascript 的其他 Issue
-
难度 4/5 3-5 天 新手友好度 48/100
yahoo/serialize-javascript#229 ·
-
Ad java script 未关闭
难度 5/5 一周以上 新手友好度 20/100
yahoo/serialize-javascript#212 · 1 条评论 ·
-
难度 4/5 3-5 天 新手友好度 45/100
yahoo/serialize-javascript#208 · 10 条评论 · 25 个 reaction ·
-
难度 3/5 1-2 天 新手友好度 35/100
yahoo/serialize-javascript#195 ·
-
难度 3/5 1-2 天 新手友好度 45/100
yahoo/serialize-javascript#182 ·
查看 yahoo/serialize-javascript 的全部 Issue
相似的 Issue
-
enhancement
难度 2/5 1-3 小时 新手友好度 70/100
babalae/bettergi-scripts-list#3674 ·
-
难度 2/5 1-3 小时 新手友好度 88/100
vadimdemedes/ink#1029 ·
-
code-quality refactoring
难度 2/5 1-3 小时 新手友好度 84/100
github/gh-aw-firewall#8816 ·
-
integration:quickjs org:external priority:backlog topic:code-interpreter topic:middleware type:feature
难度 2/5 1-3 小时 新手友好度 74/100
langchain-ai/deepagents#6450 ·
-
optimization optimization:agents-md-curator
难度 2/5 1-3 小时 新手友好度 86/100
githubnext/gh-aw-cao#13143 ·