Skip to content

harden: block prototype pollution in index.js (CWE-1321) - #197

Closed
anupamme wants to merge 1 commit into
mapbox:mainfrom
anupamme:fix-repo-geojson-vt-cwe-1321-prototype-pollution-options
Closed

anupamme wants to merge 1 commit into
mapbox:mainfrom
anupamme:fix-repo-geojson-vt-cwe-1321-prototype-pollution-options

Conversation

@anupamme

Copy link
Copy Markdown

The GeoJSONVT constructor accepts a user-controlled 'options' object and merges it using Object.assign without sanitizing prototype-polluting keys (proto, constructor, prototype). This allows an attacker to pollute the Object prototype, potentially affecting all objects in the application. This is defence-in-depth at src/index.js:29 rather than a vulnerability I can show is exploitable here — it makes the failure mode explicit and bounded. Close it freely if the pattern is intentional.

Reference: CWE-1321

What changed

  • src/index.js

Verification

No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
@anupamme
anupamme requested a review from a team as a code owner September 26, 2026 18:24
@mourner

mourner commented Sep 26, 2026

Copy link
Copy Markdown
Member

Nope, absolutely unnecessary.

@mourner mourner closed this Sep 26, 2026
@anupamme

Copy link
Copy Markdown
Author

Thanks for taking a look. Agreed. I don’t have a demonstrated attacker-controlled path to the constructor in the current API, so this is better characterised as a defense-in-depth/static-pattern finding rather than a confirmed vulnerability.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants