logo

DOJO CHALLENGE #13 Winners!

ID: 622b371d-d42a-50ba-b5a4-1e17eaf05b9c

STIX ID: report--622b371d-d42a-50ba-b5a4-1e17eaf05b9c

Feed Name: YesWeHack Blog

Threat Score
30/100

Date Published: 2021-09-24

Date Updated: 2026-07-15

...
...

This DOJO Challenge #13 write-up explains how an attacker can use prototype pollution (via constructor.prototype as an alternative to __proto__) to place a code property on an object's prototype so that a blacklist-based deletion of options.code fails, allowing execution of arbitrary JavaScript through new Function; the report includes source code, step-by-step analysis, a PoC JSON payload, and references.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.