Impact
The Phoenix JavaScript presence client performs a simple truthiness check for presence existence rather than verifying the presence of an own property. Because presence keys can be supplied by the client, an attacker may choose a key that matches a member of JavaScript’s Object.prototype, such as __proto__ or constructor. When the client looks up that key, the lookup returns the built‑in Object.prototype instead of undefined. The prototype object is truthy, so the code treats it as an existing presence and attempts to read .metas.map(...) from it, triggering an uncaught TypeError. The error propagates out of the presence message handler, leaving local state unupdated and preventing the onSync() callback from firing. Since the malicious key is echoed by the server on each presence update, every viewer of that channel experiences a persistent client‑side denial of service until the offending user disconnects. The defect does not alter Object.prototype, nor does it allow code execution; it merely causes a continuous crash of the presence sync logic for the affected topic.
Affected Systems
The issue is present in the Phoenix framework’s JavaScript presence client shipped with Phoenix. Versions affected are all releases from 1.2.0‑rc.0 up to, but not including, 1.5.15; 1.6.0‑rc.0 up to, but not including, 1.6.17; 1.7.0‑rc.0 up to, but not including, 1.7.24; and 1.8.0‑rc.0 up to, but not including, 1.8.9. Applications that allow users to provide arbitrary presence identifiers such as usernames or session IDs without validation are vulnerable.
Risk and Exploitability
An attacker with ordinary channel access can supply a malicious presence key. The resulting TypeError propagates out of the sync handler but is not caught by higher‑level code, leaving the client in a broken state until the offending user disconnects. The CVSS score of 6.3 indicates moderate severity. The EPSS score of <1% implies a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, because the exploit requires only normal user privileges and can continuously disrupt the user interface of affected channels, the risk remains material for exposed or public channels.
OpenCVE Enrichment
Github GHSA