天下漏洞,尽知其名
MEDIUM

CVE-2026-103918 oRPC 原型污染漏洞

影响攻击者可污染请求对象原型,导致继承值影响应用查询或触发异常

AI 研判

oRPC 是用于构建端到端类型安全、符合 OpenAPI 标准的 API 工具。其 @orpc/zod 的 ZodSmartCoercionPlugin 及实验性插件在处理对象和 record 属性时使用普通对象并通过原型链解析 shape 键。远程客户端在可访问带对象或 record 输入的过程时,可传入 __proto__ 替换返回请求对象的原型。

影响范围

oRPC

oRPC 1.14.10 之前的版本,涉及 @orpc/zod 的 ZodSmartCoercionPlugin 与 experimental_ZodSmartCoercionPlugin。

漏洞详情

漏洞类型为原型污染。成因是插件将对象/record 属性收集到普通对象中,并通过原型链解析 shape 键,未对 __proto__ 等特殊键做过滤。攻击者可传入 __proto__ 替换请求对象原型,使攻击者控制的继承值进入应用查询;对对象 schema,constructor、toString、__proto__ 等键还可能被解析为继承的 Zod schema,在验证前抛出未处理的 TypeError。

利用条件与风险

利用前提是远程客户端能访问使用该插件且接受对象或 record 输入的过程。全局 Object.prototype、其他对象、其他请求及其他用户不受影响,可用性影响仅限于构造的请求,而非进程级持久状态,实战风险中等。

修复建议

升级至 oRPC 1.14.10 或更高版本。临时缓解措施暂无公开信息。

原始情报

oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.10, the @orpc/zod ZodSmartCoercionPlugin and experimental_ZodSmartCoercionPlugin collect object and record properties in plain objects and resolve shape keys through the prototype chain. A remote client that can reach a procedure with an object or record input can supply __proto__ to replace the prototype of the returned request object, allowing attacker-controlled inherited values to reach application lookups. For object schemas, keys such as constructor, toString, and __proto__ can instead resolve inherited members as Zod schemas and cause an unhandled TypeError before validation. The global Object.prototype, unrelated objects, other requests, and other users are not modified, and the availability effect is limited to crafted requests rather than persistent process-wide state. This issue is fixed in version 1.14.10.