Skip to content

Patch transitive json5 prototype-pollution vulnerability via minimal npm override - #2691

Draft
jainakanksha-msft with Copilot wants to merge 2 commits into
mainfrom
copilot/fix-json5-prototype-pollution
Draft

Patch transitive json5 prototype-pollution vulnerability via minimal npm override#2691
jainakanksha-msft with Copilot wants to merge 2 commits into
mainfrom
copilot/fix-json5-prototype-pollution

Conversation

Copilot AI commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Dependabot flagged json5@0.5.1 (CVE-2022-46175 / GHSA-9c47-m6qq-7p4h), where JSON5.parse can set __proto__ on parsed objects. This PR upgrades to the lowest patched line (1.0.2) with a scoped transitive override to minimize change surface.

  • Dependency remediation

    • Added an npm override for json5 to force resolution to 1.0.2 (lowest patched version).
    • Regenerated lockfile through npm so the vulnerable 0.5.1 entry is replaced by 1.0.2.
  • Reachability assessment

    • Advisory impact is tied to JSON5.parse.
    • Repository search found no JSON5/JSON5.parse usage in runtime or test codepaths.
    • Current exposure is transitive via dev tooling (cross-varbabel-registerbabel-corejson5), so this change primarily removes scanner-detected vulnerable resolution rather than an actively exercised Azurite runtime path.
    • Confidence: High (specific API named in advisory; no callsites found).
  • Minimal change excerpt

    {
      "overrides": {
        "json5": "1.0.2",
        "undici": "^7.28.0"
      }
    }
Original prompt

This section details the Dependabot vulnerability alert you should resolve

<alert_title>Prototype Pollution in JSON5 via Parse Method</alert_title>
<alert_description>The parse method of the JSON5 library before and including version 2.2.1 does not restrict parsing of keys named __proto__, allowing specially crafted strings to pollute the prototype of the resulting object.

This vulnerability pollutes the prototype of the object returned by JSON5.parse and not the global Object prototype, which is the commonly understood definition of Prototype Pollution. However, polluting the prototype of a single object can have significant security impact for an application if the object is later used in trusted operations.

Impact

This vulnerability could allow an attacker to set arbitrary and unexpected keys on the object returned from JSON5.parse. The actual impact will depend on how applications utilize the returned object and how they filter unwanted keys, but could include denial of service, cross-site scripting, elevation of privilege, and in extreme cases, remote code execution.

Mitigation

This vulnerability is patched in json5 v2.2.2 and later. A patch has also been backported for json5 v1 in versions v1.0.2 and later.

Details

Suppose a developer wants to allow users and admins to perform some risky operation, but they want to restrict what non-admins can do. To accomplish this, they accept a JSON blob from the user, parse it using JSON5.parse, confirm that the provided data does not set some sensitive keys, and then performs the risky operation using the validated data:

const JSON5 = require('json5');

const doSomethingDangerous = (props) => {
  if (props.isAdmin) {
    console.log('Doing dangerous thing as admin.');
  } else {
    console.log('Doing dangerous thing as user.');
  }
};

const secCheckKeysSet = (obj, searchKeys) => {
  let searchKeyFound = false;
  Object.keys(obj).forEach((key) => {
    if (searchKeys.indexOf(key) > -1) {
      searchKeyFound = true;
    }
  });
  return searchKeyFound;
};

const props = JSON5.parse('{"foo": "bar"}');
if (!secCheckKeysSet(props, ['isAdmin', 'isMod'])) {
  doSomethingDangerous(props); // "Doing dangerous thing as user."
} else {
  throw new Error('Forbidden...');
}

If the user attempts to set the isAdmin key, their request will be rejected:

const props = JSON5.parse('{"foo": "bar", "isAdmin": true}');
if (!secCheckKeysSet(props, ['isAdmin', 'isMod'])) {
  doSomethingDangerous(props);
} else {
  throw new Error('Forbidden...'); // Error: Forbidden...
}

However, users can instead set the __proto__ key to {"isAdmin": true}. JSON5 will parse this key and will set the isAdmin key on the prototype of the returned object, allowing the user to bypass the security check and run their request as an admin:

const props = JSON5.parse('{"foo": "bar", "__proto__": {"isAdmin": true}}');
if (!secCheckKeysSet(props, ['isAdmin', 'isMod'])) {
  doSomethingDangerous(props); // "Doing dangerous thing as admin."
} else {
  throw new Error('Forbidden...');
}
 ```</alert_description>

<severity>high</severity>
<identifiers>GHSA-9c47-m6qq-7p4h, CVE-2022-46175</identifiers>
<package>json5</package>
<ecosystem>npm</ecosystem>
<vulnerable_versions>0.5.1</vulnerable_versions>
<patched_version>1.0.2</patched_version>
<manifest_path>package-lock.json</manifest_path>

<references>
<url>https://github.com/json5/json5/security/advisories/GHSA-9c47-m6qq-7p4h</url>
<url>https://nvd.nist.gov/vuln/detail/CVE-2022-46175</url>
<url>https://github.com/json5/json5/issues/199</url>
<url>https://github.com/json5/json5/issues/295</url>
<url>https://github.com/json5/json5/pull/298</url>
<url>https://github.com/json5/json5/commit/62a65408408d40aeea14c7869ed327acead12972</url>
<url>https://github.com/json5/json5/commit/7774c1097993bc3ce9f0ac4b722a32bf7d6871c8</url>
<url>https://lists.debian.org/debian-lts-announce/2023/11/msg00021.html</url>
<url>https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3S26TLPLVFAJTUN3VIXFDEBEXDYO22CE</url>
<url>https://github.com/advisories/GHSA-9c47-m6qq-7p4h</url>
</references>

<agent_instructions>@Copilot please go through the issues mentioned here, identify all issues, and assess whether they can be fixed.
Recommend the necessary changes.
If it is not a breaking change, let's log the issue.
Please verify all test cases and validate the runs.
</agent_instructions>

<task_instructions>Resolve this alert by updating the affected package to a non-vulnerable version. Prefer the lowest non-vulnerable version (see the patched_version field above) over the latest to minimize breaking changes. Include a Reachability Assessment section in the PR description. Review the alert_description field to understand which APIs, features, or configurations are affected, then search the codebase for usage of those specific items. If the vulnerable code path is reachable, e...

</details>



<!-- START COPILOT CODING AGENT SUFFIX -->

- Resolves Azure/Azurite alert #36

Copilot AI requested review from Copilot and removed request for Copilot August 3, 2026 08:19
Copilot AI changed the title [WIP] Fix prototype pollution vulnerability in JSON5 library Patch transitive json5 prototype-pollution vulnerability via minimal npm override Aug 3, 2026
Copilot AI requested a review from jainakanksha-msft August 3, 2026 08:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants