References https://www.sonarsource.com/blog/blitzjs-prototype-pollution https://github.com/blitz-js/superjson/security/advisories/GHSA-5888-ffcr-r425 https://nvd.nist.gov/vuln/detail/CVE-2022-23631 https://avd.aliyun.com/detail?id=AVD-2022-23631 https://nosec.org/m/share/5029.html https://www.venustech.com.cn/new_type/aqtg/20220722/24189.html https://github.com/advisories/GHSA-5888-ffcr-r425 https://security.snyk.io/vuln/SNYK-JS-SUPERJSON-2397274 https://www.zzwa.org.cn/4168/ https://cn-sec.com/archives/1237550.html
Related VulnerabilitiesPoCpackage-json: NPM package.json DisclosurePoCvlife-fastjson-rce: Vlife FastJSON - Remote Code ExecutionPoCazure-functions-hostjson-exposure: Azure Functions host.json Configuration ExposurePoCCVE-2025-1302: JSONPath Plus < 10.3.0 - Remote Code Execution(CVE-2025-9910)jsondiffpatch 0.7.2前版本跨站脚本漏洞fastjson-rce-all: Fastjson Deserialization RCEhikvision-center-fastjson-rce: 海康威视综合安防-运行管理中心-Fastjson-远程命令执行漏洞PoCCVE-2017-18349: Fastjson Insecure Deserialization - Remote Code ExecutionPoCCVE-2020-28429: geojson2kml - Command InjectionPoCyunanbao-authservice-fastjson-rce: 云匣子 FastJson反序列化RCE漏洞PoCconfig-json-exposure-fuzz: Exposed JSON Configuration FilesPoCconfig-json: Configuration File - DetectPoCauth-json: Auth.json File - Disclosure