Impact
flat-to-nested-js transforms flat hierarchy data into a nested JSON structure. Before version 1.1.2, its convert() function used attacker‑influenced values from the id and parent fields as object keys in temporary structures. If those values were set to "__proto__", the key resolved to Object.prototype, allowing the function to write attacker‑controlled properties onto the global prototype. Applications that pass untrusted flat records to convert() could thus poison the prototype chain, leading to logic corruption or a denial of service. The flaw is a classic prototype‑pollution weakness (CWE‑1321) and also violates safe key handling (CWE‑915).
Affected Systems
Any project that incorporates joaonuno:flat-to-nested-js prior to release v1.1.2 is impacted. The library is typically used to convert flat hier in a variety of JavaScript applications that rely on its public convert() function. Version information is explicitly limited to versions earlier than 1.1.2; all newer releases are considered safe.
Risk and Exploitability
The CVSS score of 7.5 indicates the vulnerability is in the high severity range. The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation. The issue is not listed in CISA’s KEV catalog, suggesting that exploitation may not be widespread yet. Attackers would need to supply crafted flat records to the convert() method, which is typically a public function or one invoked with externally sourced data. If the application does not validate or sanitize these input objects, prototype pollution can be triggered, providing a vector for logic corruption or a chain to more serious consequences if a downstream gadget is deployed. There are no existing public exploits, but the conditions for exploitation are straightforward and could be automated in a typical environment where flatToNested is used.
OpenCVE Enrichment
Github GHSA