How to Fuzz Prototype Pollution by Reusing Public CVEs for Fun and Research

7 months ago 47
BOOK THIS SPACE FOR AD
ARTICLE AD

Bug Hunting Write-up for Node.js Security

Peng Zhou

4 min read

Just now

--

I am writing this article to share some of my research experiences for hunting prototype pollution vulnerabilities across the node.js ecosystem. We have had more than 60 new prototype pollution findings in this research work and received 8 CVE numbers from Snyk when I…

Read Entire Article