vulns.co
/
GKData.io MCP

Prototype pollution

Prototype pollution is a property written onto a shared object. It is a lead until you can name the sink that property reaches, on an object you own. A polluted field with no sink is inventory.

Skill

No skill is linked for this class yet. Start with the playbook on this page.

Practice the class in the browser: PortSwigger Web Security Academy. The lab is theirs. This page is the stop condition and the disclosures.

Checklists

None linked for this class yet.

Disclosures

No public card yet.

Playbooks

Tools

  • ppmap - Prototype pollution scanner for URL gadgets. Pollution without a sink is weak; pair with the JS review playbook.

Payloads

  • Prototype Pollution - Client and server merge gadgets. Pollution without a sink is weak; pair with an XSS or RCE gadget.

Questions

The client shows __proto__ in a response. Is that the bug?

It is the primitive. The report needs the behavior that changed because that property existed: a rendered sink, a server decision, or a gadget the next page already names.

Client and server are the same hunt?

Same class, different sinks. Say which process accepted the property. Do not file a browser-only merge as remote code execution.

This page is the linked pack hunt_brief("prototype") returns on the MCP connector. Authorized testing only.