Логотип exploitDog
bind:CVE-2025-57820
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-57820

Количество 2

Количество 2

nvd логотип

CVE-2025-57820

6 месяцев назад

Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to devalue.parse could represent an object with a __proto__ property and devalue.parse does not check that an index is numeric. This could result in assigning prototypes to objects and properties, leading to prototype pollution. This issue has been fixed in version 5.3.2

EPSS: Низкий
github логотип

GHSA-vj54-72f3-p5jv

6 месяцев назад

devalue prototype pollution vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-57820

Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to devalue.parse could represent an object with a __proto__ property and devalue.parse does not check that an index is numeric. This could result in assigning prototypes to objects and properties, leading to prototype pollution. This issue has been fixed in version 5.3.2

0%
Низкий
6 месяцев назад
github логотип
GHSA-vj54-72f3-p5jv

devalue prototype pollution vulnerability

0%
Низкий
6 месяцев назад

Уязвимостей на страницу