Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-26136 — This repository contains a solution for the CVE-2023-26136 vulnerability. | Kitploit
Tools/GitHubGitHub/morrisel/cve-2023-26136
Static AnalysisVulnerability AnalysisCode AnalysisSupply Chain SecurityPapers & ResearchLearning & Education
GitHubmorrisel/cve-2023-26136

CVE-2023-26136

This repository contains a solution for the CVE-2023-26136 vulnerability.

View Repository
81 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Research on the vulnerability CVE-2023-26136

Description

Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which objects are initialized.

Objective and Fix

This project aims to provide a patched version of [email protected] that eliminates the CVE-2023-26136 vulnerability while ensuring backward compatibility.

To fix the vulnerability, we modified memstore.js to ensure that cookies are stored in an object without prototype pollution risks by replacing standard object initialization with Object.create(null). This prevents prototype manipulation through maliciously crafted cookie names.

Structure

In the tough-cookie/ directory, we can find two additional directories containing the original and patched versions of tough-cookie:

  1. Original version (Original v2.5.0/) – Unmodified tough-cookie 2.5.0, which is vulnerable.
  2. Patched version (v2.5.0-PATCHED/) – A modified version that includes a fix for CVE-2023-26136.

Installation

To install the original vulnerable version:

npm install [email protected]

Patch Details

The applied patch changes the way cookies are stored: this.idx = {}; was changed to: this.idx = Object.create(null);

This prevents attackers from injecting properties into the prototype chain and exploiting the vulnerability.

The vulnerability in tough-cookie (CVE-2023-26136) arises due to the use of a plain JavaScript object {} to store cookies. Since {} inherits from Object.prototype, it can be exploited by injecting properties like proto, leading to prototype pollution. This could allow an attacker to manipulate application behavior or cause security issues.

To mitigate this, the patch replaces {} with Object.create(null), which creates an object with no prototype ([[Prototype]]: null). This ensures that the object does not inherit any properties from Object.prototype, preventing attackers from injecting malicious properties.

By using Object.create(null), we effectively isolate the cookie store from unintended prototype inheritance, making it safer against prototype pollution attacks.

Installation Guide and Patch Instructions

To install the patched version locally, follow these steps:

  1. Extract the patched package (optional for verification):

tar -tzf tough-cookie-2.5.0.tgz

If needed, extract it:

tar -xzf tough-cookie-2.5.0.tgz

  1. Install the patched package:

npm install ./tough-cookie-2.5.0.tgz

  1. Verify the fix: Run the test script:

node index.js

Expected output:

EXPLOITED SUCCESSFULLY - for the original version

EXPLOIT FAILED - for the patched version

Node.js Compatibility

The patched version has been tested on Node.js 20 (LTS) to ensure compatibility with the latest stable runtime environment.

Repository and Fork

The original tough-cookie repository (Salesforce) is currently at version 5.1.1. Since we are working with version 2.5.0, a direct fork from the main repository isn't possible. Instead, we created a separate repository containing both the original and patched versions. You can find it here:

GitHub Repository - Forked Version

CI/CD

  • No CI/CD tools were used in this research.
  • Familiar with Docker (basic level).

Reference

For more details, visit the official CVE page: CVE-2023-26136 - NVD

Download Tool