estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed in 3.3.3.
History

Mon, 07 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed in 3.3.3.
Title estree-util-value-to-estree allows prototype pollution in generated ESTree
Weaknesses CWE-1321
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-07T15:45:04.415Z

Reserved: 2025-04-01T21:57:32.953Z

Link: CVE-2025-32014

cve-icon Vulnrichment

Updated: 2025-04-07T15:37:53.960Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-07T15:15:44.593

Modified: 2025-04-08T18:14:17.307

Link: CVE-2025-32014

cve-icon Redhat

No data.