Hunt Nodejs

Hunt Node.js specific vulnerabilities — Prototype Pollution → RCE chains (lodash/merge/assign), Express trust proxy misconfiguration, child_process/eval injection, template engine SSTI (EJS/Pug/Handlebars), path traversal in file servers, require() injection, environment variable exfil via /proc/self/environ. Use when target runs Node.js/Express/Fastify/NestJS/Koa.

uphiago cfb4f11 12.1 KB Updated

File contents

uphiago/recon-skills/tree/main/redteam/hunt-nodejs commit cfb4f1184e

Frequently asked questions

npx skillmds@latest add uphiago/hunt-nodejs