GHSA-gcgf-fh7c-8gf2: Medium severity npm/@orpc/zod vulnerability

Published Oct 5, 2026
·
Updated

Summary

ZodSmartCoercionPlugin and experimentalZodSmartCoercionPlugin mishandle object keys that name Object.prototype members. Both coerce request input before validation, so any client that can reach a procedure whose input schema contains an object or a record can:

1. replace the prototype of the coerced input object, and 2. make a request fail with an unhandled TypeError by sending a key such as constructor.

This is the same class of bug as GHSA-4h5r-cv8j-4456 in @orpc/json-schema, in a different package.

This is not global prototype pollution

The global Object.prototype is never modified. No shared or global state is written, so other objects in the process, other requests, and other users are not affected.

What changes is the prototype of one object: the value the coercer returns for the request that carried the payload. That object is passed on to validation and to the procedure handler, then discarded when the request ends. An ordinary {} created anywhere else in the application is unaffected.

Details

1. proto replaces the prototype of the coerced value

Coerced properties were collected into a plain {}, so newObj['proto'] = value triggers the inherited proto setter instead of creating an own property. Verified on 1.14.8 against a record schema, in both plugins:

schema: z.record(z.string()) input: {"a":"1","proto":{"polluted":true}}

Object.keys(result) => ["a"] // the proto entry is dropped from the output result.polluted => true // the attacker object is now this object's prototype ({}).polluted => undefined // Object.prototype is untouched

The returned value inherits attacker controlled properties, and any consumer reading them through the prototype chain, such as a handler checking input.isAdmin, an Object.assign copy, or a config lookup, sees data the client never legitimately supplied. How far that goes depends on what the application does with the coerced input. There is no generic escalation path.

This affects the record branch of both plugins, and the object branch of both plugins for any key that does not first trigger the error below.

2. Sub-schemas resolved through the prototype chain

The object branch looked up sub-schemas with shape[key], which returns inherited members for keys such as constructor, toString and proto. Those values, for example the Object constructor, were then dereferenced as Zod schemas:

schema: z.object({ a: z.number() }) input: { a: '123', constructor: '456' }

zod 3 => TypeError: Cannot read properties of undefined (reading 'Symbol(ORPCCUSTOMZODDEF)') zod 4 => TypeError: Cannot read properties of undefined (reading 'def')

Coercion throws before the assignment, so for object schemas these keys break the request rather than injecting a prototype. Any client can trigger this on its own requests. It does not affect other clients or the process as a whole.

Impact

Any oRPC server that installs ZodSmartCoercionPlugin or experimentalZodSmartCoercionPlugin from @orpc/zod and has at least one procedure whose input schema contains an object or a record. No authentication or user interaction is required beyond what the procedure itself demands.

The effect is scoped to the request that sent the payload. Because no global state is written, one request cannot influence another, and restarting the process is not needed to recover.

Patch

Fixed in 1.14.10.

In packages/zod/src/coercer.ts and packages/zod/src/zod4/coercer.ts:

- collect coerced object and record properties into NullProtoObj, the null prototype helper already used for untrusted keys in bracket-notation.ts and rpc-matcher.ts, so proto stays an ordinary own property and is preserved in the output - guard the shape lookup with Object.hasOwn, so unknown keys fall through to catchall as they already do for every other name

PR: middleapi/orpc#1727

Workarounds

Reject or strip request payloads containing proto, constructor or prototype keys before they reach the handler, or remove the plugin if automatic coercion is not required.

Note that SmartCoercionPlugin from @orpc/json-schema, the recommended replacement for these plugins, was affected by the same class of issue (GHSA-4h5r-cv8j-4456) and is fixed in the same release.

Credit

Reported and fixed internally.

Affected Software

1 affected componentFixes available
npm/@orpc/zod<1.14.10
1.14.10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@orpc/zod to a version that resolves this vulnerability.

    Fixed in 1.14.10
  2. Upgrade

    Upgrade @orpc/zod to a version that resolves this vulnerability.

    Fixed in 1.14.10
  3. Upgrade

    Upgrade @orpc/json-schema to a version that resolves this vulnerability.

    Fixed in 1.14.10
  4. Remove

    Remove @orpc/zod ZodSmartCoercionPlugin and experimental_ZodSmartCoercionPlugin from your environment.

    Remove the plugin if automatic coercion is not required.

  5. Compensating control

    Reject or strip request payloads containing __proto__, constructor, or prototype keys before they reach the handler.

Event History

Oct 5, 2026
Advisory Published
via GitHub·05:32 PM
Data Sourced
via GitHub·05:32 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments using ZodSmartCoercionPlugin or experimental_ZodSmartCoercionPlugin are exposed when a client can reach a procedure whose input schema includes an object or record. The affected coercion occurs before validation.

2

Does this affect other requests or globally pollute Object.prototype?

No. The global Object.prototype is not modified, and no shared state is written. Only the coerced input object for the malicious request has its prototype changed; it is discarded when that request ends.

3

What can an attacker do with a crafted request?

A client can replace the prototype of the coerced input object using a __proto__ key. Sending a key such as constructor can also cause the request to fail with an unhandled TypeError.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203