Prototype Pollution Detection for Node.Js Applications: A Review

Authors

  • Nitya N Hegde JSS Academy of Technical Education, Bengaluru, Karnataka, India
  • Mamatha G JSS Academy of Technical Education, Bengaluru, Karnataka, India

Keywords:

Client side, JavaScript, Node.js applications, Prototype pollution

Abstract

Prototype pollution is a critical vulnerability that affects JavaScript environments, including Node.js. This vulnerability arises from the dynamic nature of JavaScript, allowing attackers to manipulate the prototype of objects and inject malicious properties into them. In Node.js applications, prototype pollution can lead to severe security threats, including Remote Code Execution (RCE) and Cross Site Scripting (XSS) attacks.
Research in the Prototype pollution vulnerability detection and exploitation in Node.js has seen significant advancements. Various techniques, such as Symbolic/ Concolic testing, static analysis, and dynamic taint analysis, have been employed to effectively detect and exploit prototype pollution vulnerabilities. Tools and frameworks, such as UOPF (Undefined oriented Programming Framework) and Silent Spring, have been developed to automate detecting and chaining prototype pollution gadgets in Node.js template engines.
Prototype pollution vulnerabilities in Node.js are particularly challenging due to the complex nature of JavaScript applications and the diversity of libraries and frameworks used in Node.js development. Therefore, researchers continue to explore new methods and techniques to improve the detection and mitigation of prototype pollution vulnerabilities in Node.js environments.

Author Biographies

Nitya N Hegde, JSS Academy of Technical Education, Bengaluru, Karnataka, India

Under Graduate Student, Department of Information Science & Engineering

Mamatha G, JSS Academy of Technical Education, Bengaluru, Karnataka, India

Assistant Professor, Department of Information Science & Engineering

Published

2024-07-11

How to Cite

N Hegde, N., & Mamatha G. (2024). Prototype Pollution Detection for Node.Js Applications: A Review. Journal of Cyber Security, Privacy Issues and Challenges, 3(2), 23–32. Retrieved from https://matjournals.net/engineering/index.php/JCSPIC/article/view/682

Issue

Section

Articles