Prototype pollution
Prototype pollution is a property written onto a shared object. It is a lead until you can name the sink that property reaches, on an object you own. A polluted field with no sink is inventory.
Skill
No skill is linked for this class yet. Start with the playbook on this page.
Practice the class in the browser: PortSwigger Web Security Academy. The lab is theirs. This page is the stop condition and the disclosures.
Checklists
None linked for this class yet.
Disclosures
No public card yet.
Playbooks
- Prototype Pollution (client & server) - Inject properties into Object.prototype to change app behavior - client-side DOM XSS or server-side RCE via gadget chains.
Tools
- ppmap - Prototype pollution scanner for URL gadgets. Pollution without a sink is weak; pair with the JS review playbook.
Payloads
- Prototype Pollution - Client and server merge gadgets. Pollution without a sink is weak; pair with an XSS or RCE gadget.
Questions
The client shows __proto__ in a response. Is that the bug?
It is the primitive. The report needs the behavior that changed because that property existed: a rendered sink, a server decision, or a gadget the next page already names.
Client and server are the same hunt?
Same class, different sinks. Say which process accepted the property. Do not file a browser-only merge as remote code execution.
This page is the linked pack hunt_brief("prototype") returns on the MCP connector. Authorized testing only.