Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js

Mikhail Shcherbakov, Musard Balliu, Cristian-Alexandru Staicu. Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js. In Joseph A. Calandrino, Carmela Troncoso, editors, 32nd USENIX Security Symposium, USENIX Security 2023, Anaheim, CA, USA, August 9-11, 2023. pages 5521-5538, USENIX Association, 2023. [doi]

Authors

Mikhail Shcherbakov

This author has not been identified. Look up 'Mikhail Shcherbakov' in Google

Musard Balliu

This author has not been identified. Look up 'Musard Balliu' in Google

Cristian-Alexandru Staicu

This author has not been identified. Look up 'Cristian-Alexandru Staicu' in Google