ZDS-2025-0142CRITICAL9.8CWE-1321DISCLOSEDdisclosed 2025-04-14

Prototype pollution via crafted JSON chunk

/summary

Summary

Unsanitized property assignment during streamed JSON parsing allows a remote attacker to mutate Object.prototype, leading to RCE in Express middleware contexts.

/poc

Proof-of-concept

# Reproduction steps redacted under coordinated disclosure.
# Full PoC will be published with the advisory at embargo expiry.

$ zds reproduce ZDS-2025-0142
ZDS-2025-0142 — Prototype pollution via crafted JSON chunk · ZeroDayShield