Логотип exploitDog
bind:CVE-2025-68130
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-68130

Количество 2

Количество 2

nvd логотип

CVE-2025-68130

около 2 месяцев назад

tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27.0 and prior to versions 10.45.3 and 11.8.0, a A prototype pollution vulnerability exists in `@trpc/server`'s `formDataToObject` function, which is used by the Next.js App Router adapter. An attacker can pollute `Object.prototype` by submitting specially crafted FormData field names, potentially leading to authorization bypass, denial of service, or other security impacts. Note that this vulnerability is only present when using `experimental_caller` / `experimental_nextAppDirCaller`. Versions 10.45.3 and 11.8.0 fix the issue.

EPSS: Низкий
github логотип

GHSA-43p4-m455-4f4j

около 2 месяцев назад

tRPC has possible prototype pollution in `experimental_nextAppDirCaller`

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-68130

tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27.0 and prior to versions 10.45.3 and 11.8.0, a A prototype pollution vulnerability exists in `@trpc/server`'s `formDataToObject` function, which is used by the Next.js App Router adapter. An attacker can pollute `Object.prototype` by submitting specially crafted FormData field names, potentially leading to authorization bypass, denial of service, or other security impacts. Note that this vulnerability is only present when using `experimental_caller` / `experimental_nextAppDirCaller`. Versions 10.45.3 and 11.8.0 fix the issue.

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-43p4-m455-4f4j

tRPC has possible prototype pollution in `experimental_nextAppDirCaller`

0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу