{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/sift/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sift:sift:17.1.3:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-85625"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["sift (17.1.3)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","code-execution","prototype-pollution","javascript","cve-2026-85625"],"_cs_type":"advisory","_cs_vendors":["sift"],"content_html":"\u003cp\u003eThe sift.js library, specifically version 17.1.3, contains a high-severity vulnerability (CVE-2026-85625) due to the use of for...in loops for query key enumeration. By iterating over the object prototype chain, the library inadvertently dispatches matched operator keys, including the sensitive $where operator. Under the default configuration, where CSP_ENABLED is not set, sift utilizes the new Function constructor to execute the string value associated with the $where operator. This allows an attacker who can either perform prototype pollution - injecting a $where property into Object.prototype - or pass a crafted query object containing a malicious $where string, to achieve arbitrary JavaScript execution within the host process. This vulnerability poses a significant risk to Node.js applications that utilize sift.js to filter untrusted user input, as the execution occurs within the context of the running application.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to execute arbitrary JavaScript code on the server hosting the affected application. This can lead to full application compromise, unauthorized access to data, and further lateral movement within the environment. Given the widespread use of data filtering libraries in web frameworks, this vulnerability affects any sector utilizing sift.js for query processing without explicit security hardening.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade sift.js to a version where prototype chain walking is prevented or the $where operator is disabled by default.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation for all query objects passed to the sift library to ensure they do not contain unexpected operator keys.\u003c/li\u003e\n\u003cli\u003eIf version upgrading is not immediately possible, explicitly set the CSP_ENABLED configuration to true or define an environment-based mitigation to disable dangerous evaluation patterns in sift.js.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-04T15:28:18Z","date_published":"2026-09-04T15:28:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sift-js-prototype-pollution/","summary":"The sift.js library version 17.1.3 is vulnerable to arbitrary code execution when processing untrusted input that leverages prototype pollution or malicious $where operator strings to invoke the new Function constructor.","title":"Arbitrary Code Execution in sift.js via Prototype Pollution and $where Operator","url":"https://feed.craftedsignal.io/briefs/2026-09-sift-js-prototype-pollution/"}],"language":"en","title":"CraftedSignal Threat Feed - Sift","version":"https://jsonfeed.org/version/1.1"}