Details
Alert ID 210008-2
Alert Type Tool
Status alpha
Risk Medium
CWE 1321
WASC
Technologies Targeted All
Tags CWE-1321
OWASP_2021_A08
OWASP_2025_A05
TOOL_PTK

Summary

Tainted data reached a dangerous prototype key write.

Generated by OWASP PTK IAST Module

Solution

• Reject __proto__, constructor, and prototype keys during object merge and parsing. • Use safe merge utilities and create null-prototype maps where appropriate.

Other Info

References

Code

src/ptk/background/iast/modules/modules.json