Skip to content

Mass assignment and parameter pollution: preventing privilege escalation in REST and GraphQL APIs

How mass assignment and HTTP parameter pollution allow attackers to overwrite administrative attributes (isAdmin, role, price) in API models, and how to prevent it.

By BugSnaps Security Research · · 7 min read

Modern web frameworks emphasize developer productivity by offering automatic binding of incoming JSON request payloads directly into database models or ORM entities. While convenient, this practice—known as Mass Assignment or Over-Posting—creates severe privilege escalation vulnerabilities.

How mass assignment leads to account takeover

Consider a user profile update route: `PUT /api/user/profile`. The client is expected to send `{ "name": "Jane", "bio": "Developer" }`. The vulnerable backend executes: `User.update(req.body, { where: { id: req.user.id } })`.

  • Privilege escalation: an attacker sends `{ "role": "admin", "is_verified": true }`, overwriting privileged database fields.
  • Billing bypass: updating subscription objects with `{ "plan": "enterprise", "expires_at": "2099-01-01" }`.
  • Account recovery hijack: modifying internal flags like `{ "mfa_enabled": false, "email_verified": true }`.

Defending with explicit Data Transfer Objects (DTOs)

Never pass unsanitized request payloads directly to database update methods. Enforce strict Data Transfer Objects (DTOs) or schema validation libraries (such as Zod, Joi, or Pydantic) that explicitly whitelist only permitted, editable fields.

Enforce an allowlist of permitted fields at the controller layer. Never bind raw request bodies directly to persistent database entities.

Run a real pentest on your app - free.

Sign in, prove you own the domain, and MyPentest maps and tests it. No credit card.