estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed in 3.3.3.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 07 Apr 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed in 3.3.3. | |
Title | estree-util-value-to-estree allows prototype pollution in generated ESTree | |
Weaknesses | CWE-1321 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-07T15:45:04.415Z
Reserved: 2025-04-01T21:57:32.953Z
Link: CVE-2025-32014

Updated: 2025-04-07T15:37:53.960Z

Status : Awaiting Analysis
Published: 2025-04-07T15:15:44.593
Modified: 2025-04-08T18:14:17.307
Link: CVE-2025-32014

No data.