Описание
Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)
Prototype Pollution in internal assign() helper in Linkify allows remote attackers to execute arbitrary JavaScript (Stored or Reflected XSS) via injection of event handlers through unfiltered proto property. This issue affects Linkify version 4.3.1 and is fixed in 4.3.2.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-8101
- https://github.com/nfrasser/linkifyjs/commit/931d3e28b68951b8f898ea4d6504696346b485b0
- https://caverav.cl/posts/linkify-xss/linkify-xss
- https://fluidattacks.com/advisories/charly
- https://github.com/nfrasser/linkifyjs/releases/tag/v4.3.2
- https://www.npmjs.com/package/linkifyjs
Пакеты
linkifyjs
= 4.3.1
4.3.2
Связанные уязвимости
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Linkify (linkifyjs) allows XSS Targeting HTML Attributes and Manipulating User-Controlled Variables.This issue affects Linkify: from 4.3.1 before 4.3.2.
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Linkify (linkifyjs) allows XSS Targeting HTML Attributes and Manipulating User-Controlled Variables.This issue affects Linkify: from 4.3.1 before 4.3.2.