Ch. 1 · JavaScript

JavaScript Prototype Pollution at Input Boundaries

JavaScript Prototype Pollution at Input Boundaries. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readadvancedupdated Oct 3, 2026

Untrusted keys must not influence shared prototypes or inherited security decisions. Parse expected fields rather than recursively merging arbitrary objects.

Step-by-step walkthrough

Step 1: Treat keys as untrusted input

External property names can affect more than business data when passed into unsafe merge or assignment logic. Define the configuration’s supported keys and shapes before deciding how to construct the trusted result. Unknown nested fields need a policy too.

Step 2: Construct validated output

An allowlist parser reads permitted own fields and validates each value. Map or null-prototype dictionaries can represent arbitrary-key collections without ordinary inherited property behavior, but surrounding code must still avoid unsafe copying and unchecked security decisions.

Step 3: Keep authorization independent

Do not infer privileges from inherited properties or a loosely merged configuration object. Authorization should consume deliberately validated data from a trusted source. Test the complete merge and read path, because blocking one spelling alone may leave another unsafe nested path.

Worked scenario

An allowlist parser constructs configuration from permitted own properties; dictionary data can use Map or null-prototype objects.

function parsePreferences(input) {
  if (!input || typeof input !== 'object') throw new Error('Invalid input');
  const output = {theme: 'light'};
  if (Object.hasOwn(input, 'theme')) {
    if (!['light', 'dark'].includes(input.theme)) throw new Error('Invalid theme');
    output.theme = input.theme;
  }
  return output;
}
console.log(parsePreferences({theme: 'dark', unexpected: true}));
JavaScript

Walk through the example

The parser copies one known value rather than merging every incoming property. It deliberately ignores unknown fields in this example; an API may instead reject them. Arrays, accessors or hostile in-memory objects need stricter treatment if they are valid boundary inputs. JSON decoding and shape validation should be explicit.

Common mistake

Filtering one spelling does not protect every nested merge path. Value validation is still required.

Verify the behavior

Test missing fields, unknown keys, inherited theme values and invalid nested input. Add regression inputs targeting the actual merge implementation if one exists. Confirm a rejected or ignored key does not modify Object.prototype or affect later authorization-related objects.

Interview exercise

Accept external configuration safely.

Answer and reasoning

Validate its schema, construct explicit output and test unexpected nested keys. Keep authorization checks on validated, deliberately owned properties.

Follow-up discussion

Is an allowlist enough for arbitrary JavaScript objects? Getters and unusual prototypes can still execute behavior, so define the accepted source and representation. Does Map eliminate all security risk? No: it changes entry-key semantics, while validation and privilege checks remain essential.

Continue learning

Compare the scenario with the JavaScript interview questions and test your understanding with the JavaScript MCQs. For terminology and implementation details, consult the reference material.

More in JavaScript

read ✓JavaScript · mid

JavaScript Date and Timezone Pitfalls

Parse and format dates without timezone surprises: zero-based months, date-only versus date-time parsing, and why UTC storage avoids drift.

~3 min readread →
read ✓JavaScript · mid

JavaScript Number Precision and BigInt

Why 0.1 + 0.2 is not 0.3, where safe integer range ends, and when BigInt is the right tool for large identifiers and money.

~2 min readread →
esc