CVE-2025-64718

⚪ Do wiadomości

Zanieczyszczenie prototypu w js-yaml umożliwia atakującym modyfikację obiektów po przetworzeniu YAML.

CVSS
5.3
EPSS
0.4%
Exploit
none
Vendor
nodeca
Opis źródłowy (NVD)

js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1 and 3.14.2. Users can protect against this kind of attack on the server by using `node --disable-proto=delete` or `deno` (in Deno, pollution protection is on by default).

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2025-11-13 16:15:57 UTC
Ostatnia modyfikacja (NVD)2026-10-07 21:10:00 UTC
Referencje