{"categories":["Web Security Academy","Prototype pollution"],"html":"<iframe src=\"https://hatenablog-parts.com/embed?url=https%3A%2F%2Fcysec148.hatenablog.com%2Fentry%2F2025%2F09%2F17%2F060451\" title=\"JSON\u306b\u3088\u308bPrototype Pollution\uff08\u30d7\u30ed\u30c8\u30bf\u30a4\u30d7\u6c5a\u67d3\uff09 - Shikata Ga Nai\" class=\"embed-card embed-blogcard\" scrolling=\"no\" frameborder=\"0\" style=\"display: block; width: 100%; height: 190px; max-width: 500px; margin: 10px 0px;\"></iframe>","blog_title":"Shikata Ga Nai","url":"https://cysec148.hatenablog.com/entry/2025/09/17/060451","author_name":"ThisIsOne","published":"2025-09-17 06:04:51","description":"Hello there, ('\u03c9')\u30ce \ud83e\udde8 \u653b\u6483\u306b\u4f7f\u308f\u308c\u308b\u60aa\u610f\u3042\u308bJSON \u653b\u6483\u8005\u304c\u4ee5\u4e0b\u306e\u3088\u3046\u306aJSON\u3092\u9001\u4fe1\u3057\u305f\u3068\u3057\u307e\u3059\uff1a { \"__proto__\": { \"evilProperty\": \"payload\" } } \u4f8b\u3048\u3070\u3001WebSocket\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u3084AJAX\u30ea\u30af\u30a8\u30b9\u30c8\u306a\u3069\u3067\u30b5\u30fc\u30d0\u3084\u30d5\u30ed\u30f3\u30c8\u30a8\u30f3\u30c9\u306b\u9001\u4fe1\u3055\u308c\u308b\u3053\u3068\u304c\u3042\u308a\u307e\u3059\u3002 \ud83e\udd16 JavaScript\u3067\u3069\u3046\u306a\u308b\uff1f \u3053\u308c\u3092 JSON.parse() \u3067\u30d1\u30fc\u30b9\u3059\u308b\u3068\uff1a const objectFromJson = JSON.parse('{\"__proto__\": {\"evilProperty\": \"payload\"}}'); \u3053\u306e\u3068\u304d o\u2026","author_url":"https://blog.hatena.ne.jp/ThisIsOne/","image_url":null,"version":"1.0","provider_url":"https://hatena.blog","title":"JSON\u306b\u3088\u308bPrototype Pollution\uff08\u30d7\u30ed\u30c8\u30bf\u30a4\u30d7\u6c5a\u67d3\uff09","provider_name":"Hatena Blog","blog_url":"https://cysec148.hatenablog.com/","width":"100%","height":"190","type":"rich"}