CVE-2020-8158 is a prototype-pollution vulnerability in TypeORM versions earlier than 0.2.25. An attacker may add or modify JavaScript object properties through unsafe prototype manipulation. The resulting altered application-object behavior can potentially be leveraged to cause denial of service or influence query construction in a manner that enables SQL injection.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone TypeScript proof-of-concept for CVE-2020-8158, a prototype pollution vulnerability in TypeORM versions prior to 0.2.25. It is not part of a larger exploit framework. The repository is small and primarily consists of one real code file, test.ts, plus supporting configuration files for Docker, TypeORM, npm, and TypeScript. Core exploit behavior: test.ts defines TypeORM entities (Post and Category), opens live connections to MySQL and MongoDB on localhost, and then saves attacker-controlled JSON containing a __proto__ property via mongoConnection.manager.save(Post, post). The crafted object is intended to pollute inherited properties used later by TypeORM. After the save attempt, the script performs mysqlConnection.manager.find(Category, {}) and comments indicate the polluted prototype can inject a where clause such as name='hacked'. The code comments also include alternate payloads for denial of service (recursive polluted object) and query manipulation using skip/take. Repository structure: - test.ts: main PoC and effective exploit entry point. - package.json: pins vulnerable dependency typeorm 0.2.24 and defines ts-node scripts. - docker-compose.yml: provisions MongoDB, MariaDB, and PostgreSQL locally for testing. - ormconfig.json / ormconfig.multi.json: database connection settings for localhost services. - Makefile: convenience wrappers for setup, Docker lifecycle, and test execution. - README.md: vulnerability overview, impact claims, and setup notes, though it references files not present in this archive. Notable observations: - The exploit is a local/lab PoC rather than a remote weaponized exploit. - It requires a vulnerable TypeORM environment and reachable databases. - The included code demonstrates exploitation mechanics rather than delivering a shell or post-exploitation payload. - README mentions additional files (vulnerable-app.ts, exploit.ts, patched-app.ts) that are absent; the actual exploit logic present is in test.ts. - PostgreSQL is configured in Docker and cleanup logic, but the demonstrated exploit path in code uses MongoDB input to influence MySQL-side behavior.
This repository is a proof-of-concept (PoC) for CVE-2020-8158, a critical prototype pollution vulnerability in TypeORM versions prior to 0.2.25. The PoC demonstrates how an attacker can exploit improper object deserialization in TypeORM to pollute the prototype chain, potentially leading to denial of service, SQL injection, or arbitrary code execution. The main exploit logic is implemented in 'test.ts', which connects to local MySQL, MongoDB, and PostgreSQL instances (as configured in the provided Docker Compose and JSON config files), and attempts to save a crafted object containing a '__proto__' property. This triggers the vulnerability in TypeORM's entity hydration process. The repository includes configuration files for setting up the environment, but the core exploit is a local attack requiring the attacker to control input to the application using a vulnerable TypeORM version. No remote network endpoints are targeted; the attack is demonstrated against local database services. The repository is structured for easy testing and demonstration, with Makefile targets for setup, exploitation, and cleanup.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.