DOI: 10.1145/3848632 ISSN: 1049-331X

Effective Fuzzing-based Prototype Pollution Detection via Forced Execution and Template Synthesis

Dezhen Kong, Peisen Yao, Jiakun Liu, Lingfeng Bao

Prototype pollution is a critical class of taint-style vulnerabilities in JavaScript programs, enabling attackers to tamper with object prototypes and thereby alter program behavior in unexpected and often dangerous ways. Despite its severity, existing detection techniques struggle with excessive false positives and poor scalability.

In this work, we present

Forecast
, a lightweight fuzzing-based approach that integrates both forced execution based dynamic analysis and template-based exploit generation to effectively detect prototype pollution vulnerabilities and generate working exploits.
Forecast
enables better flexibility and scalability and avoids imprecise modeling of JavaScript syntax in static analysis.

Our evaluation of curated benchmarks and real-world Node.js packages shows that

Forecast
identifies more vulnerabilities than prior approaches, including
Explode.js
,
Graph.js
,
ObjLupAnsys
, and
ODGen
. Specifically, on the benchmark of known vulnerabilities from prior works,
Forecast
can identify 228 out of 238 vulnerabilities and generate working exploits for them.
Forecast
also discovers 24 zero-day vulnerabilities between over 60k popular packages collected from npm registry. Additionally, compared to
ODGen
and
ObjLupAnsys
,
Forecast
demonstrates better scalability by mitigating time-out for many packages.