GHSA-6xv4-9cqp-92rh
MODERATECVE-2025-57353The Runtime components of messageformat package for Node.js version 3.0.1 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the processing of message data, an attacker can manipulate the prototype chain of JavaScript objects by providing specially crafted input. This can result in the injection of arbitrary properties into the Object.prototyp
- Affected
- = 3.0.1
- Fixed in
- 3.0.2
- Weakness
- CWE-1321
- Published
- 2025-09-24
- Source
- github