GHSA-2mhw-wcx5-v3xj: Medium severity npm/scim-patch vulnerability

Published Sep 28, 2026
·
Updated

Summary

Incomplete Prototype Pollution Fix Allows Mutation of Inherited Built-in Method Objects

scim-patch blocks direct dangerous path segments such as proto, constructor, and prototype, but still traverses inherited properties when applying SCIM patch paths.

An attacker who controls a SCIM PATCH operation can use paths such as toString.polluted to mutate shared built-in function objects, for example Object.prototype.toString.

Impact

A malicious patch can add attacker-controlled properties to inherited built-in method objects. The impact is narrower than direct Object.prototype pollution, but the mutation is process-global and may affect application logic that reads properties from inherited methods.

Details

Affected code paths:

- navigate() reads inherited properties via schema[subPath] - assign() uses key in obj, which treats inherited properties as existing

Because inherited keys are followed, safe-looking path segments such as toString can resolve to shared built-in objects.

PoC

js const assert = require("node:assert/strict"); const { scimPatch } = require("./lib/src/scimPatch");

const victim = { schemas: ["urn:ietf:params:scim:schemas:core:2.0:User"], userName: "alice", active: true, emails: [{ value: "alice@example.com", primary: true }], meta: { created: "x", lastModified: "x", resourceType: "User" } };

try { assert.equal(({}).toString.scimPatchPolluted, undefined);

scimPatch(victim, [ { op: "add", path: "toString.scimPatchPolluted", value: "polluted" } ]);

assert.equal(({}).toString.scimPatchPolluted, "polluted"); console.log(({}).toString.scimPatchPolluted); } finally { delete Object.prototype.toString.scimPatchPolluted; }

Output:

text polluted

A no-path operation with a dotted value key is also affected:

js scimPatch(victim, [ { op: "add", value: { "toString.noPathPolluted": "polluted" } } ]);

Remediation

Do not traverse inherited properties while resolving patch paths. Use own-property checks such as Object.hasOwn(obj, key) and create missing containers only for safe own keys.

Keep the existing denylist for proto, constructor, and prototype as defense in depth.

Affected Software

1 affected componentFixes available
npm/scim-patch<0.9.2
0.9.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/scim-patch to a version that resolves this vulnerability.

    Fixed in 0.9.2
  2. Compensating control

    When resolving SCIM PATCH paths, do not traverse inherited properties: use own-property checks such as Object.hasOwn(obj, key), create missing containers only for safe own keys, and retain the denylist for __proto__, constructor, and prototype as defense in depth.

Event History

Sep 28, 2026
Advisory Published
via GitHub·02:01 PM
Data Sourced
via GitHub·02:01 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What level of access does an attacker need to exploit this issue?

The attacker must be able to control a SCIM PATCH operation. No user interaction is required.

2

What can be modified by a successful malicious patch?

A patch path using an inherited name such as toString can resolve to a shared built-in method object and add attacker-controlled properties to it. The resulting mutation is process-global, although it is narrower than direct Object.prototype pollution.

3

Why do blocked path segments not fully prevent exploitation?

Although direct __proto__, constructor, and prototype segments are blocked, the affected path handling follows inherited properties. navigate() reads inherited values through schema[subPath], and assign() treats inherited keys as existing through key in obj.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203