Advanced prototype pollution playbook — server-side RCE, client-side gadgets, filter bypasses, and detection techniques. Companion to ../prototype-pollution/ for basics. Use when you've confirmed pollution and need to escalate to code execution or find framework-specific gadgets.
日本語の概要は準備中です。原文の説明を表示しています。
yaklang/hack-skills☆ 2,4252026年9月13日 更新
Identify and exploit Prototype Pollution vulnerabilities in JavaScript/Node.js applications. This skill covers the progression from polluting `Object.prototype` to identifying functional gadgets (like `child_process.spawn`) to achieve Remote Code Execution (RCE).
日本語の概要は準備中です。原文の説明を表示しています。
ShulkwiSEC/bb-huge☆ 242026年7月11日 更新
Advanced prototype pollution playbook — server-side RCE, client-side gadgets, filter bypasses, and detection techniques. Companion to ../prototype-pollution/ for basics. Use when you've confirmed pollution and need to escalate to code execution or find framework-specific gadgets.
日本語の概要は準備中です。原文の説明を表示しています。
ShulkwiSEC/bb-huge☆ 242026年7月11日 更新
Identify and exploit Prototype Pollution vulnerabilities in JavaScript applications to achieve client-side Cross-Site Scripting (XSS), bypass authentication, or execute Remote Code Execution (RCE) on Node.js servers by manipulating the core Object prototype.
日本語の概要は準備中です。原文の説明を表示しています。
ShulkwiSEC/bb-huge☆ 242026年7月11日 更新
JavaScript prototype pollution — Object.prototype'u kirleterek auth bypass, RCE, XSS gadget chains (server-side Node.js ve client-side)
日本語の概要は準備中です。原文の説明を表示しています。
MustafaKemal0146/fetih☆ 52026年10月11日 更新
Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.
日本語の概要は準備中です。原文の説明を表示しています。
aniket2348823/Vul-Agent☆ 22026年6月9日 更新
Prototype pollution testing for JavaScript stacks. Use when user input is merged into objects (query parsers, JSON bodies, deep assign), when configuring libraries via untrusted keys, or when hunting RCE gadgets via polluted Object.prototype in Node or the browser.
日本語の概要は準備中です。原文の説明を表示しています。
yaklang/hack-skills☆ 2,4252026年9月13日 更新
Use when pentesting a web application or API — injection, XSS/CSP, SSRF/cloud-metadata, HTTP desync & cache poisoning, SSTI/prototype-pollution/deserialization, JWT/OAuth/GraphQL/IDOR, business logic & single-packet race
日本語の概要は準備中です。原文の説明を表示しています。
hypnguyen1209/offensive-claude☆ 3892026年9月28日 更新
Use when auditing source code for vulnerabilities — drive CodeQL/Semgrep/Joern to taint untrusted data source-to-sink across injection, memory safety, deserialization/prototype-pollution, secrets/crypto/authz/race, and supply-chain risks
日本語の概要は準備中です。原文の説明を表示しています。
hypnguyen1209/offensive-claude☆ 3892026年9月28日 更新
Living catalogue of 7 known hazard entries (SE-01 through SE-07) specific to agent-studio: Windows backslash paths, prototype pollution, hook exit codes, async swallowing, ReDoS in glob-to-regex, DST arithmetic, array mutation during iteration. Each entry: symptom, root cause, fix, test assertion.
日本語の概要は準備中です。原文の説明を表示しています。
oimiragieo/agent-studio☆ 432026年7月14日 更新
Prototype pollution testing for JavaScript stacks. Use when user input is merged into objects (query parsers, JSON bodies, deep assign), when configuring libraries via untrusted keys, or when hunting RCE gadgets via polluted Object.prototype in Node or the browser.
日本語の概要は準備中です。原文の説明を表示しています。
ShulkwiSEC/bb-huge☆ 242026年7月11日 更新
在授权渗透测试中挖掘 JavaScript 原型污染(prototype pollution,服务端 Node.js 与客户端)。当目标把用户可控的键名递归合并进对象(merge/extend/set/clone、JSON body、query 解析)时使用——典型场景:用 `__proto__`/`constructor.prototype` 注入属性,污染全局原型,进而 DoS、改逻辑、配合 gadget 提权到 XSS/RCE。适用目标类型 Web / REST API(Node.js) / 前端。触发场景包括用户说"测下原型污染""这个 merge 能不能 __proto__""污染原型打 RCE/XSS""lodash/jquery 有没有污染点"。输出:污染点 + 可用 gadget 判定 + 反射证据的 finding(含 killed 记录)。
日本語の概要は準備中です。原文の説明を表示しています。
galact-byte/galact-Skills☆ 72026年10月2日 更新
Detect prototype pollution via object merge/clone/assign operations where __proto__ or constructor.prototype keys can modify Object.prototype.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新