Advisories for Npm/Scim-Patch package

2026

scim-patch: Mutation of Inherited Built-in Method Objects

Incomplete Prototype Pollution Fix Allows Mutation of Inherited Built-in Method Objects scim-patch blocks direct dangerous path segments such as proto, constructor, and prototype, but still traverses inherited properties when applying SCIM patch paths. An attacker who controls a SCIM PATCH operation can use paths such as toString.polluted to mutate shared built-in function objects, for example Object.prototype.toString.

scimPatch vulnerable to prototype pollution via unfiltered keys in patch

scim-patch performs prototype pollution when applying a SCIM PATCH operation whose value object contains a key like "proto.someProp". After one such patch, Object.prototype.someProp is set process-wide, affecting every plain object in the Node process. Any service that calls scimPatch() on attacker-controlled JSON (i.e. any SCIM endpoint accepting PATCH from an external IdP) is exploitable on a stock Node runtime.