Effective Fuzzing-based Prototype Pollution Detection via Forced Execution and Template Synthesis
Prototype pollution is a critical class of taint-style vulnerabilities in JavaScript programs, enabling attackers to tamper with object prototypes and thereby alter program behavior in unexpected and often dangerous ways. Despite its severity, existing detection techniques struggle with excessive false positives and poor scalability. In this work, we present Forecast , a lightweight fuzzing-based approach that integrates both forced execution based dynamic analysis and template-based exploit generation to effectively detect prototype pollution vulnerabilities and generate working exploits. Forecast enables better flexibility and scalability and avoids imprecise modeling of JavaScript syntax in static analysis. Our evaluation of curated benchmarks and real-world Node.js packages shows that Forecast identifies more vulnerabilities than prior approaches, including Explode.js , Graph.js , ObjLupAnsys , and ODGen . Specifically, on the benchmark of known vulnerabilities from prior works, Forecast can identify 228 out of 238 vulnerabilities and generate working exploits for them. Forecast also discovers 24 zero-day vulnerabilities between over 60k popular packages collected from npm registry. Additionally, compared to ODGen and ObjLupAnsys , Forecast demonstrates better scalability by mitigating time-out for many packages.
Authors
- Lingfeng Bao (ORCID: https://orcid.org/0000-0003-1846-0921)
- Peisen Yao (ORCID: https://orcid.org/0000-0003-0342-9518)
- Jiakun Liu (ORCID: https://orcid.org/0000-0002-7273-6709)
- Dezhen Kong (ORCID: https://orcid.org/0000-0001-7627-1294)
Institutions
- Harbin Institute of Technology (CN)
- Zhejiang University (CN)
Publication Details
- Journal
- ACM Transactions on Software Engineering and Methodology
- Published
- 2026-09-24
- DOI
- https://doi.org/10.1145/3848632
- Primary Topic
- Security and Verification in Computing
- Type
- article
- Field-Weighted Citation Impact
- 0.00