Effective Fuzzing-based Prototype Pollution Detection via Forced Execution and Template Synthesis

Prototype pollution is a critical class of taint-style vulnerabilities in JavaScript programs, enabling attackers to tamper with object prototypes and thereby alter program behavior in unexpected and often dangerous ways. Despite its severity, existing detection techniques struggle with excessive false positives and poor scalability. In this work, we present Forecast , a lightweight fuzzing-based approach that integrates both forced execution based dynamic analysis and template-based exploit generation to effectively detect prototype pollution vulnerabilities and generate working exploits. Forecast enables better flexibility and scalability and avoids imprecise modeling of JavaScript syntax in static analysis. Our evaluation of curated benchmarks and real-world Node.js packages shows that Forecast identifies more vulnerabilities than prior approaches, including Explode.js , Graph.js , ObjLupAnsys , and ODGen . Specifically, on the benchmark of known vulnerabilities from prior works, Forecast can identify 228 out of 238 vulnerabilities and generate working exploits for them. Forecast also discovers 24 zero-day vulnerabilities between over 60k popular packages collected from npm registry. Additionally, compared to ODGen and ObjLupAnsys , Forecast demonstrates better scalability by mitigating time-out for many packages.

Authors

Institutions

Publication Details

Journal
ACM Transactions on Software Engineering and Methodology
Published
2026-09-24
DOI
https://doi.org/10.1145/3848632
Primary Topic
Security and Verification in Computing
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Effective Fuzzing-based Prototype Pollution Detection via Forced Execution and Template Synthesis

Lingfeng Bao, Peisen Yao, Jiakun Liu, Dezhen Kong
ACM Transactions on Software Engineering and Methodology
Security and Verification in Computing
article

Effective Fuzzing-based Prototype Pollution Detection via Forced Execution and Template Synthesis

Lingfeng Bao, Peisen Yao, Jiakun Liu, Dezhen Kong
article en

Abstract

Prototype pollution is a critical class of taint-style vulnerabilities in JavaScript programs, enabling attackers to tamper with object prototypes and thereby alter program behavior in unexpected and often dangerous ways. Despite its severity, existing detection techniques struggle with excessive false positives and poor scalability. In this work, we present Forecast , a lightweight fuzzing-based approach that integrates both forced execution based dynamic analysis and template-based exploit generation to effectively detect prototype pollution vulnerabilities and generate working exploits. Forecast enables better flexibility and scalability and avoids imprecise modeling of JavaScript syntax in static analysis. Our evaluation of curated benchmarks and real-world Node.js packages shows that Forecast identifies more vulnerabilities than prior approaches, including Explode.js , Graph.js , ObjLupAnsys , and ODGen . Specifically, on the benchmark of known vulnerabilities from prior works, Forecast can identify 228 out of 238 vulnerabilities and generate working exploits for them. Forecast also discovers 24 zero-day vulnerabilities between over 60k popular packages collected from npm registry. Additionally, compared to ODGen and ObjLupAnsys , Forecast demonstrates better scalability by mitigating time-out for many packages.

ACM Transactions on Software Engineering and Methodology
Harbin Institute of Technology (CN), Zhejiang University (CN)
Openalex Percentile: Top 9%
Security and Verification in Computing
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Effective Fuzzing-based Prototype Pollution Detection via Forced Execution and Template Synthesis — Lingfeng Bao, Peisen Yao, et al. · ACM Transactions on Software Engineering and Methodology (2026) | TGRS Research Map | TGRS