Логотип exploitDog
bind:CVE-2025-57349
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-57349

Количество 2

Количество 2

nvd логотип

CVE-2025-57349

5 месяцев назад

The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message key paths in versions prior to 2.3.0. The flaw arises when processing nested message keys containing special characters (e.g., __proto__ ), which can lead to unintended modification of the JavaScript Object prototype. This vulnerability may allow a remote attacker to inject properties into the global object prototype via specially crafted message input, potentially causing denial of service or other undefined behaviors in applications using the affected component.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xfqm-j7pc-xrfc

5 месяцев назад

messageformat has a prototype pollution vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-57349

The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message key paths in versions prior to 2.3.0. The flaw arises when processing nested message keys containing special characters (e.g., __proto__ ), which can lead to unintended modification of the JavaScript Object prototype. This vulnerability may allow a remote attacker to inject properties into the global object prototype via specially crafted message input, potentially causing denial of service or other undefined behaviors in applications using the affected component.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xfqm-j7pc-xrfc

messageformat has a prototype pollution vulnerability

0%
Низкий
5 месяцев назад

Уязвимостей на страницу