vulns.co
/
GKData.io MCP

Back to Playbooks

Prototype Pollution (client & server)

Inject properties into Object.prototype to change app behavior - client-side DOM XSS or server-side RCE via gadget chains.

Tags: prototype-pollution, javascript, nodejs, gadgets

Level: advanced

Method

  1. Test for the sink

    Add __proto__[test]=polluted via query, JSON body, or merge functions. On the client, check window.Object.prototype.test in console; on server, look for behavior changes.

    curl 'https://target.com/api?__proto__[test]=polluted'

    Tools: Burp Suite

  2. Client-side: find a gadget

    Look for sinks that read a polluted property (e.g., library options) and flow to innerHTML/script. DOM Invader (Burp) automates gadget hunting.

    Tools: Burp Suite

  3. Server-side: escalate to RCE

    In Node apps, pollute properties consumed by child_process, template engines, or spawn options to achieve command execution.

Field notes

  • JSON bodies with a literal "__proto__" key often bypass naive query-string filters.
  • Client gadgets are library-specific - jQuery, Lodash, and sanitizers each have known ones.

References