Web Prototype Pollution

JavaScript prototype pollution (client & server) → XSS, auth bypass, RCE via gadgets. Load on Node.js/JS apps that merge user objects: query/JSON parsing, `Object.assign`/deep-merge, lodash/jQuery.extend, config merges. Signals: __proto__, constructor.prototype in params, Node backend, client-side sinks.

NoorQureshi 66f2b0c 2.2 KB Updated

File contents

NoorQureshi/SploitAgent/tree/main/skills/web/web-prototype-pollution commit 66f2b0c485

Frequently asked questions

npx skillmds@latest add noorqureshi/web-prototype-pollution