CVE-2026-103036 oRPC @orpc/json-schema 原型污染漏洞
影响攻击者可污染单个请求对象的原型,影响处理器逻辑与配置查找
oRPC 是一个用于构建端到端类型安全并符合 OpenAPI 标准的 API 工具。其 @orpc/json-schema 包中的 SmartCoercionPlugin 在 1.14.9 之前使用 JsonSchemaCoercer 以普通对象收集属性,并通过原型链解析 schema.properties 条目。远程客户端可借此注入 __proto__ 或 constructor、toString 等原型成员名,绕过强制转换检查。
影响范围
oRPC @orpc/json-schema 1.14.9 之前的版本;具体受影响版本范围暂无更详细的公开信息。
漏洞详情
漏洞类型为原型污染。成因是 JsonSchemaCoercer 在收集对象属性时使用普通对象并通过原型链查找 schema.properties,未对 __proto__、constructor、toString 等特殊键做过滤。攻击者可向带对象输入 schema 的 procedure 发送恶意请求,用 __proto__ 替换单个被强制转换请求对象的原型,或让继承属性被当作子 schema 通过校验,从而影响 handler、Object.assign 或配置查找。
利用条件与风险
利用前提是攻击者能访问带有对象输入 schema 的 procedure,且目标使用受影响版本。该漏洞仅影响单个请求对象,不污染全局 Object.prototype、其他请求或其他用户,且下游 schema 校验仍会执行,实战风险中等。
修复建议
官方已在 1.14.9 版本中修复,建议升级至 1.14.9 或更高版本。临时缓解措施暂无公开信息,可考虑对输入中的 __proto__、constructor、prototype 等键进行过滤。
oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.9, the @orpc/json-schema SmartCoercionPlugin uses JsonSchemaCoercer to collect object properties in a plain object and to resolve schema.properties entries through the prototype chain. A remote client that can reach a procedure with an object input schema can supply __proto__ to replace the prototype of the single coerced request object, or supply Object.prototype member names such as constructor and toString so inherited values are treated as sub-schemas and pass the coercer’s satisfaction check. Attacker-controlled inherited properties can consequently affect handler, Object.assign, or configuration lookups, while legitimate __proto__ properties are dropped. The global Object.prototype, unrelated objects, other requests, and other users are not modified, and downstream schema validation still runs. This issue is fixed in version 1.14.9.