CVE-2023-26136 is a prototype-pollution vulnerability in tough-cookie versions earlier than 4.1.3. Improper cookie handling and object initialization in the cookie memory store allow prototype attributes to be modified when a CookieJar is configured with rejectPublicSuffixes=false.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository demonstrates and patches CVE-2023-26136, a prototype pollution vulnerability in the tough-cookie Node.js library (versions before 4.1.3, specifically 2.5.0). The vulnerability allows an attacker to pollute Object.prototype by setting a cookie with a domain such as '__proto__' when the CookieJar is configured with 'rejectPublicSuffixes: false'. The repository structure includes: - The original vulnerable tough-cookie 2.5.0 source (tough-cookie/Original v2.5.0/) - A patched version (tough-cookie/v2.5.0-PATCHED/) where all object initializations in MemoryCookieStore use Object.create(null) to prevent prototype pollution - A diff file (changes.diff) and a patch diff (patch_diff.txt) documenting the fix - A unit test (test-cve-2023-26136.js) that verifies the vulnerability is fixed - An exploit demonstration script (tough-cookie/index.js) that shows exploitation is possible in the original version but fails in the patched version The exploit works by setting a cookie with a malicious domain ('__proto__'), which, in the vulnerable version, pollutes the Object.prototype and can lead to application logic manipulation, security bypass, or denial of service. The patch ensures that cookie storage objects do not inherit from Object.prototype, thus preventing this attack vector. The repository is a comprehensive demonstration and fix for the vulnerability, including test and demonstration scripts.
This repository is a patched fork of the tough-cookie JavaScript library (v2.5.0) that addresses the prototype pollution vulnerability (CVE-2023-26136). The vulnerability allows an attacker to set a cookie with Domain=__proto__, which pollutes the JavaScript Object prototype, potentially leading to privilege escalation, denial of service, or remote code execution in applications using the vulnerable library. The main exploit demonstration is in index.js, which attempts to set such a cookie and checks if the prototype is polluted. The patch (in lib/memstore.js) uses Object.create(null) to create prototype-free objects, preventing the attack. The repository includes comprehensive unit tests, including test/prototype_pollution_test.js, to verify the fix. The exploit is operational and demonstrates the vulnerability and its mitigation. The main attack vector is through network input (malicious cookies), but the exploit is demonstrated locally. The repository structure is typical for a Node.js package, with source code in lib/, tests in test/, and supporting files for Docker and CI. The patched package is provided as tough-cookie-2.5.0-PATCHED.tgz.
This repository is a research and proof-of-concept (POC) project for CVE-2023-26136, a prototype pollution vulnerability in the tough-cookie Node.js library (versions before 4.1.3, demonstrated on 2.5.0). The repository contains two main subdirectories: 'Original v2.5.0' (the unmodified, vulnerable version) and 'v2.5.0-PATCHED' (a version with the vulnerability fixed by using Object.create(null) for cookie storage). The exploit is demonstrated in 'tough-cookie/index.js', which sets a malicious cookie with the domain '__proto__', triggering prototype pollution in the vulnerable version. The test script outputs 'EXPLOITED SUCCESSFULLY' for the vulnerable version and 'EXPLOIT FAILED' for the patched version, confirming the effectiveness of the patch. The repository is structured to allow easy testing and verification of the vulnerability and its fix, and is not part of a larger exploit framework. No network endpoints or external services are targeted; the exploit is local and demonstrates the impact of prototype pollution via crafted cookie names.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prototype pollution vulnerability in tough-cookie mentioned only as background comparison to the primary js-cookie flaw.
A prototype-pollution vulnerability in tough-cookie's cookie memstore.
Prototype-pollution vulnerability in the tough-cookie cookie memstore.
A prototype-pollution vulnerability in tough-cookie's cookie memstore.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.