JavaScript · Prototype · Senior · Scenario
What is prototype pollution, and how do you mitigate it in application code?
Short Interview Answer
Attackers inject properties into `Object.prototype` (e.g. via recursive merges of `__proto__`), affecting all objects; mitigate with safe merges, null-prototype maps, and hardened parsers.
Detailed Explanation
If user-controlled JSON is deep-merged unsafely, keys like `__proto__` or `constructor.prototype` can assign to the prototype chain. Then checks like `if (obj.isAdmin)` may become true on ordinary objects. Mitigations: use `Object.create(null)` for dictionaries, `Map` instead of objects, block `__proto__`/`prototype`/`constructor` keys in merges, use libraries with safe defaults, freeze prototypes in locked-down environments, and validate payloads with schema parsers. Prefer `Object.hasOwn(obj, key)` over truthiness of inherited props.
Example
// Dangerous pattern sketch — do not use with user input
// merge(target, JSON.parse(userJson))
const map = Object.create(null);
map.admin = true; // no inherited keysInterview Tip
Connect to security reviews of merge utilities — high signal for senior roles.
Common Mistake
Thinking prototype pollution only affects Node or only affects JSON.parse itself (parse alone is usually fine; unsafe merge is the usual bug).