Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-95jq-xph2-cx9h

Опубликовано: 26 июл. 2025
Источник: github
Github: Прошло ревью
CVSS4: 8.8

Описание

Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)

Prototype Pollution in internal assign() helper in Linkify allows remote attackers to execute arbitrary JavaScript (Stored or Reflected XSS) via injection of event handlers through unfiltered proto property. This issue affects Linkify version 4.3.1 and is fixed in 4.3.2.

Пакеты

Наименование

linkifyjs

npm
Затронутые версииВерсия исправления

= 4.3.1

4.3.2

EPSS

Процентиль: 41%
0.00501
Низкий

8.8 High

CVSS4

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 8.6
redhat
около 1 года назад

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Linkify (linkifyjs) allows XSS Targeting HTML Attributes and Manipulating User-Controlled Variables.This issue affects Linkify: from 4.3.1 before 4.3.2.

nvd
около 1 года назад

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Linkify (linkifyjs) allows XSS Targeting HTML Attributes and Manipulating User-Controlled Variables.This issue affects Linkify: from 4.3.1 before 4.3.2.

EPSS

Процентиль: 41%
0.00501
Низкий

8.8 High

CVSS4

Дефекты

CWE-1321