Update dependency @orpc/client to v1.13.6 [SECURITY] - #216
Merged
Conversation
Contributor
Author
Branch automerge failureThis PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.
|
renovate
Bot
force-pushed
the
renovate/npm-orpc-client-vulnerability
branch
from
July 22, 2026 08:59
4353cb9 to
7e0922a
Compare
commit: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.10.0→1.13.6@orpc/clienthas Prototype Pollution viaStandardRPCJsonSerializerDeserializationCVE-2026-28794 / GHSA-m272-9rp6-32mc
More information
Details
Summary
A critical Prototype Pollution vulnerability exists in the RPC JSON deserializer of the
@orpc/clientpackage. The vulnerability allows unauthenticated, remote attackers to inject arbitrary properties into the globalObject.prototype. Because this pollution persists for the lifetime of the Node.js process and affects all objects, it can lead to severe security breaches, including authentication bypass, denial of service, and potentially Remote Code Execution.Vulnerability Details
The root cause lies in the
deserialize()method ofStandardRPCJsonSerializer. When processing attacker-controlled path segments from themetaandmapsarrays, the deserializer fails to implement validation or sanitization for dangerous JavaScript object keys, specifically__proto__andconstructor:https://github.com/middleapi/orpc/blob/819ed2e0897b18a5d6a4ca85ba68568f055004a1/packages/client/src/adapters/standard/rpc-json-serializer.ts#L137-L213
There are two primary distinct write vectors available to an attacker:
metavector: Writes type-constrained values (e.g.,Map,Set,Date) to arbitrary object paths.mapsvector: Allows the injection of arbitrary string values. This occurs because the return value ofgetBlob(i)(which relies onFormData.get(i.toString())) is castas Blob. Since this is strictly a TypeScript compile-time cast, the runtime execution allows standard text fields to return as arbitrary strings.Crucially, this deserialization process occurs at the very beginning of the request lifecycle before any Zod schema validation takes place. Consequently, a malicious payload will successfully pollute the prototype even if the request is subsequently rejected by the validation layer.
This issue impacts all server adapters utilizing the RPC protocol.
Proof of Concept
To reproduce the vulnerability, set up the playgrounds/astro environment and start the development server using
pnpm dev.Run the following
curlcommand to send a crafted payload:curl -X POST http://localhost:4321/rpc/planet/create \ -F 'data={"json":{},"meta":[],"maps":[["__proto__","role"]]}' \ -F '0=admin'Result: The deserializer evaluates
maps, follows the__proto__path, and maps index0to the string"admin". This immediately appliesObject.prototype.role = "admin"across the entire Node.js server instance.Impact
Servers relying on
StandardRPCJsonSerializerfor deserialization are immediately susceptible to global prototype pollution. The potential impacts including:if (user.role === "admin"), the application will evaluate this astruefor all users globally.toString) or set objects into unexpected states, causing the application to crash or throw unhandled exceptions globally.Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.