Prototype Pollution (client & server)
Inject properties into Object.prototype to change app behavior - client-side DOM XSS or server-side RCE via gadget chains.
Tags: prototype-pollution, javascript, nodejs, gadgets
Level: advanced
Method
Test for the sink
Add __proto__[test]=polluted via query, JSON body, or merge functions. On the client, check window.Object.prototype.test in console; on server, look for behavior changes.
curl 'https://target.com/api?__proto__[test]=polluted'Tools: Burp Suite
Client-side: find a gadget
Look for sinks that read a polluted property (e.g., library options) and flow to innerHTML/script. DOM Invader (Burp) automates gadget hunting.
Tools: Burp Suite
Server-side: escalate to RCE
In Node apps, pollute properties consumed by child_process, template engines, or spawn options to achieve command execution.
Field notes
- JSON bodies with a literal "__proto__" key often bypass naive query-string filters.
- Client gadgets are library-specific - jQuery, Lodash, and sanitizers each have known ones.