Express Prototype Pollution

How to test for and exploit prototype pollution vulnerabilities in Express.js applications. Use this skill whenever you're pentesting Node.js/Express applications, analyzing JSON parsing vulnerabilities, or investigating server-side prototype pollution. Make sure to use this skill when you see JSON body parsing, lodash/underscore merge operations, or need to test for prototype pollution gadgets like XSS via content-type manipulation, header injection, or status code changes.

abelrguezr Updated

File contents

abelrguezr/hacktricks-skills/tree/main/skills/pentesting-web/deserialization/nodejs-proto-prototype-pollution/express-prototype-pollution-gadgets commit 135bb1db9e

Frequently asked questions

npx skillmds@latest add abelrguezr/express-prototype-pollution