
Laboratorio educativo que demuestra la contaminación de prototipos CVE-2020-7598 en minimist con una aplicación vulnerable Node.js/Express, un payload de exploit y un recorrido de omisión de autenticación para investigación en seguridad.
const assert = require('assert');
const $defineProperty = require('es-define-property');
if ($defineProperty) {
assert.equal($defineProperty, Object.defineProperty);
} else if (Object.defineProperty) {
assert.equal($defineProperty, false, 'this is IE 8');
} else {
assert.equal($defineProperty, false, 'this is an ES3 engine');
}
Simply clone the repo, npm install, and run npm test
Please email @ljharb or see https://tidelift.com/security if you have a potential security vulnerability to report.