Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Investigate Detection for Prototype Pollution

Đang mở
#95 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
38/100
Loại issue
Tính năng
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Đình trệ
Công nghệ
git, typescript
Lĩnh vực
security, testing-qa

Hướng nghiên cứu

Start by searching the OSSF CVE Benchmark dataset for prototype-pollution examples, then use archeogit or manual git history inspection to identify introducing commits and save the vulnerable diffs. Run /security:analyze to establish a baseline, review GEMINI.md if detection needs improvement, and re-run it after the prompt and benchmark updates. Done means improved detection and 3-5 clear examples added to the official internal benchmark dataset.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Description

Prototype pollution is a critical JavaScript vulnerability where an attacker can modify the prototype of a base object. This can lead to application-wide logic tampering, cross-site scripting (XSS), denial of service (DoS), or even remote code execution.

We need to ensure our security extension can effectively identify these vulnerabilities in code changes e.g. see https://github.com/gemini-cli-extensions/security/issues/90. This investigation will involve curating a dataset of real-world examples, baselining our current detection capabilities, enhancing our prompt, and updating our benchmark dataset to prevent regressions.

Action Items
  • [ ] 1. Data Curation & Analysis
    • [ ] Systematically search the OSSF CVE Benchmark dataset for clear examples of prototype pollution vulnerabilities (e.g., CVEs related to unsafe object merges).
  • [ ] 2. Vulnerability Introduction Analysis
    • [ ] For a curated subset (5-10) of the best examples, use archeogit or manual git history inspection to find the specific commit that introduced the vulnerability.
    • [ ] Save these "vulnerable diffs" for testing.
  • [ ] 3. Baseline Current Capabilities
    • [ ] Run the current security extension (/security:analyze) against the collection of vulnerable diffs.
    • [ ] Document the detection rate (e.g., "Detected 1/10"). This is our baseline.
  • [ ] 4. Enhance Detection Prompt (If Necessary)
    • [ ] Based on the results from step 3, update the GEMINI.md prompt.
    • [ ] Add "Prototype Pollution" as a new item, likely under the "Injection Vulnerabilities" category.
    • [ ] The new prompt instruction should guide the model to look for the specific patterns identified in step 1 (e.g., "Analyze for prototype pollution vulnerabilities, such as unsafe recursive object merges or direct modification of __proto__ or constructor.prototype from user-controlled input.").
  • [ ] 5. Validate and Update Benchmark
    • [ ] Re-run the security extension (with the updated prompt) against the vulnerable diffs and confirm the detection rate has improved significantly.
    • [ ] Select the 3-5 clearest examples and add them to our official internal benchmark dataset to ensure we continue to catch this vulnerability class in the future.
Ngôn ngữ chính
TypeScript
Star
794
Fork
58
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của gemini-cli-extensions/security

Tất cả issue của gemini-cli-extensions/security

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.