fix(shared): prevent prototype injection in set util - #1744
Merged
dinwwwh merged 1 commit intoJul 29, 2026
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
More templates
@orpc/ai-sdk
@orpc/arktype
@orpc/bun
@orpc/client
@orpc/cloudflare
@orpc/contract
@orpc/experimental-effect
@orpc/evlog
@orpc/json-schema
@orpc/nest
@orpc/next
@orpc/openapi
@orpc/opentelemetry
@orpc/pinia-colada
@orpc/pino
@orpc/publisher
@orpc/ratelimit
@orpc/server
@orpc/shared
@orpc/swr
@orpc/tanstack-query
@orpc/trpc
@orpc/valibot
@orpc/zod
commit: |
Contributor
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Contributor
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes — hardens set() against prototype injection by mirroring the Object.hasOwn traversal guard already used in get(), and switching writes to Object.defineProperty so keys like __proto__ are created as own data properties rather than triggering the inherited setter.
- Add
Object.hasOwntraversal guard — intermediate paths like__proto__andconstructorare treated as absent when not own properties, preventing traversal intoObject.prototype. - Switch writes to
Object.defineProperty— creates own writable/enumerable/configurable data properties for every key, including__proto__, instead of triggering the inherited setter that would swap the prototype. - Add pollution-vector tests — covers
['__proto__', 'polluted'],['constructor', 'prototype', 'polluted'], and a standalone['__proto__']set.
DeepSeek Pro (free via Pullfrog for OSS) | 𝕏
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What
Hardens the
setutil in@orpc/sharedagainst prototype injection.Previously, a path like
['__proto__', 'polluted']would read the inherited__proto__getter, walk intoObject.prototype, and write onto it — polluting every object.['constructor', 'prototype', 'x']reached the same place through theObjectconstructor.How
Mirrors the
Object.hasOwnguard thatgetalready uses:__proto__,constructor, …) are treated as absent, so a fresh plain object is created instead of walking the prototype chain.Object.defineProperty(writable/enumerable/configurable), which creates an own data property even for keys like__proto__instead of triggering the inherited setter that would swap the object's prototype.Includes tests for the
__proto__andconstructor.prototypepollution vectors.