Количество 2
Количество 2
CVE-2025-32014
estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed in 3.3.3.
GHSA-f7f6-9jq7-3rqj
estree-util-value-to-estree allows prototype pollution in generated ESTree
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-32014 estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed in 3.3.3. | 1% Низкий | 10 месяцев назад | ||
GHSA-f7f6-9jq7-3rqj estree-util-value-to-estree allows prototype pollution in generated ESTree | 1% Низкий | 10 месяцев назад |
Уязвимостей на страницу