
This repository contains a solution for the CVE-2023-26136 vulnerability.
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which objects are initialized.
This project aims to provide a patched version of [email protected] that eliminates the CVE-2023-26136 vulnerability while ensuring backward compatibility.
To fix the vulnerability, we modified memstore.js to ensure that cookies are stored in an object without prototype pollution risks by replacing standard object initialization with Object.create(null). This prevents prototype manipulation through maliciously crafted cookie names.
In the tough-cookie/ directory, we can find two additional directories containing the original and patched versions of tough-cookie:
Original v2.5.0/) – Unmodified tough-cookie 2.5.0, which is vulnerable.v2.5.0-PATCHED/) – A modified version that includes a fix for CVE-2023-26136.To install the original vulnerable version:
npm install [email protected]
The applied patch changes the way cookies are stored: this.idx = {};
was changed to: this.idx = Object.create(null);
This prevents attackers from injecting properties into the prototype chain and exploiting the vulnerability.
The vulnerability in tough-cookie (CVE-2023-26136) arises due to the use of a plain JavaScript object {} to store cookies. Since {} inherits from Object.prototype, it can be exploited by injecting properties like proto, leading to prototype pollution. This could allow an attacker to manipulate application behavior or cause security issues.
To mitigate this, the patch replaces {} with Object.create(null), which creates an object with no prototype ([[Prototype]]: null). This ensures that the object does not inherit any properties from Object.prototype, preventing attackers from injecting malicious properties.
By using Object.create(null), we effectively isolate the cookie store from unintended prototype inheritance, making it safer against prototype pollution attacks.
To install the patched version locally, follow these steps:
tar -tzf tough-cookie-2.5.0.tgz
If needed, extract it:
tar -xzf tough-cookie-2.5.0.tgz
npm install ./tough-cookie-2.5.0.tgz
node index.js
Expected output:
EXPLOITED SUCCESSFULLY - for the original version
EXPLOIT FAILED - for the patched version
The patched version has been tested on Node.js 20 (LTS) to ensure compatibility with the latest stable runtime environment.
The original tough-cookie repository (Salesforce) is currently at version 5.1.1. Since we are working with version 2.5.0, a direct fork from the main repository isn't possible. Instead, we created a separate repository containing both the original and patched versions. You can find it here:
GitHub Repository - Forked Version
For more details, visit the official CVE page: CVE-2023-26136 - NVD