DOI: 10.1145/3848632 ISSN: 1049-331X
Effective Fuzzing-based Prototype Pollution Detection via Forced Execution and Template Synthesis
Dezhen Kong, Peisen Yao, Jiakun Liu, Lingfeng BaoPrototype pollution is a critical class of taint-style vulnerabilities in JavaScript programs, enabling attackers to tamper with object prototypes and thereby alter program behavior in unexpected and often dangerous ways. Despite its severity, existing detection techniques struggle with excessive false positives and poor scalability.
In this work, we present
Forecast
, a lightweight fuzzing-based approach that integrates both forced execution based dynamic analysis and template-based exploit generation to effectively detect prototype pollution vulnerabilities and generate working exploits.
Forecast
enables better flexibility and scalability and avoids imprecise modeling of JavaScript syntax in static analysis.
Our evaluation of curated benchmarks and real-world Node.js packages shows that
Forecast
identifies more vulnerabilities than prior approaches, including
Explode.js
,
Graph.js
,
ObjLupAnsys
, and
ODGen
. Specifically, on the benchmark of known vulnerabilities from prior works,
Forecast
can identify 228 out of 238 vulnerabilities and generate working exploits for them.
Forecast
also discovers 24 zero-day vulnerabilities between over 60k popular packages collected from npm registry. Additionally, compared to
ODGen
and
ObjLupAnsys
,
Forecast
demonstrates better scalability by mitigating time-out for many packages.