GHSA-xfqm-j7pc-xrfc
LOWCVE-2025-57349The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message key paths in versions prior to 2.3.0. The flaw arises when processing nested message keys containing special characters (e.g., proto ), which can lead to unintended modification of the JavaScript Object prototype. This vu
- Affected
- < 2.3.0
- Fixed in
- 3.0.0-beta.0
- Weakness
- CWE-1321
- Published
- 2025-09-24
- Source
- github