webmedium
4llD4y
0xl4ugh
Task: Node.js Express app with flatnest and happy-dom. Solution: Prototype pollution via circular reference bypass in flatnest to enable JavaScript in happy-dom, then VM escape via this.constructor.constructor to access process.binding(fs) for file reading.
$ ls tags/ techniques/
prototype_pollution_via_circular_referencevm_escapeprocess_binding_fs
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]