deno/cli/tests/proto_exploit.js
2020-03-15 11:34:22 +01:00

6 lines
159 B
JavaScript

const payload = `{ "__proto__": null }`;
const obj = {};
console.log("Before: " + obj);
Object.assign(obj, JSON.parse(payload));
console.log("After: " + obj);