Server-side JavaScript runs attacker-reachable values in Node.js, and two classes of flaw matter here. One is direct evaluation, where input reaches a construct that compiles and runs JavaScript. The other is prototype pollution, which never evaluates attacker code directly but corrupts the shared Object.prototype so that properties the application reads later take values the attacker chose. The second is the subtler and more common server-side exposure, because the polluting request and the point where the damage is realized are usually far apart in the code.
- Prototype pollution covers the server-side Node case: the deep-merge and recursive-assign sinks, the
__proto__andconstructor.prototypepolluting payloads, and the escalation from poisoned defaults to authorization bypass and gadget-driven command execution.
Browser-side DOM prototype pollution shares the root cause but has a different sink surface and gadget set, and is covered separately.