Логотип exploitDog
bind:CVE-2025-66456
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-66456

Количество 2

Количество 2

nvd логотип

CVE-2025-66456

2 месяца назад

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 through 1.4.16 contain a prototype pollution vulnerability in `mergeDeep` after merging results of two standard schema validations with the same key. Due to the ordering of merging, there must be an any type that is set as a standalone guard, to allow for the `__proto__ prop` to be merged. When combined with GHSA-8vch-m3f4-q8jf this allows for a full RCE by an attacker. This issue is fixed in version 1.4.17. To workaround, remove the `__proto__ key` from body.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-hxj9-33pp-j2cc

2 месяца назад

Elysia vulnerable to prototype pollution with multiple standalone schema validation

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-66456

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 through 1.4.16 contain a prototype pollution vulnerability in `mergeDeep` after merging results of two standard schema validations with the same key. Due to the ordering of merging, there must be an any type that is set as a standalone guard, to allow for the `__proto__ prop` to be merged. When combined with GHSA-8vch-m3f4-q8jf this allows for a full RCE by an attacker. This issue is fixed in version 1.4.17. To workaround, remove the `__proto__ key` from body.

CVSS3: 9.8
0%
Низкий
2 месяца назад
github логотип
GHSA-hxj9-33pp-j2cc

Elysia vulnerable to prototype pollution with multiple standalone schema validation

0%
Низкий
2 месяца назад

Уязвимостей на страницу