The maintainers of the Node.js package object-path released a series of fixes for prototype pollution flaws affecting applications that use the library in inherited-properties mode through includeInheritedProps or withInheritedProps. The vulnerable behavior involved methods such as set(), del(), empty(), push(), and insert(), where attacker-controlled paths could target magic properties like __proto__ and constructor.prototype and potentially modify object prototypes. The package documentation states that the default object-path instance in versions 0.11.0 and later was not affected.
A follow-up hardening change closed a bypass of the earlier mitigation by blocking dangerous paths supplied as non-string or non-numeric values, including nested array path components. Repository tests show the library now rejects attempts to write through prototype-linked paths and raises errors containing "For security reasons" when objectPath.withInheritedProps.set is used with those values. Version 0.11.8 also added protections to get(), causing it to throw when code attempts to access restricted properties such as __proto__ or constructor in inherited-props mode.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Version 0.11.8 added protections so get() throws an exception when code attempts to access magic properties such as __proto__ or constructor while using inherited-props mode. This extended the library's prototype pollution defenses beyond write operations.
Version 0.11.6 fixed a bypass of the earlier 0.11.5 mitigation that could be triggered using non-string or non-numeric path values in inherited-props mode. This addressed a way around the initial prototype pollution protections.
Version 0.11.5 introduced a security fix for prototype pollution affecting functions such as set(), del(), empty(), push(), and insert() when object-path was used with inherited properties enabled via includeInheritedProps or withInheritedProps. The default object-path instance in versions 0.11.0 and later was stated to be unaffected.
A GitHub commit added security tests showing that dangerous paths like __proto__ and constructor.prototype must be blocked even when path components are supplied in nested arrays or other non-string forms. The tests verified that objectPath.withInheritedProps.set throws a security error instead of modifying Object.prototype or class prototypes.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.