Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-57820

Опубликовано: 26 авг. 2025
Источник: nvd
EPSS Низкий

Описание

Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to devalue.parse could represent an object with a proto property and devalue.parse does not check that an index is numeric. This could result in assigning prototypes to objects and properties, leading to prototype pollution. This issue has been fixed in version 5.3.2

EPSS

Процентиль: 32%
0.00123
Низкий

Дефекты

CWE-1321

Связанные уязвимости

github
6 месяцев назад

devalue prototype pollution vulnerability

EPSS

Процентиль: 32%
0.00123
Низкий

Дефекты

CWE-1321