GHSA-8v65-5fw5-23wj
LOWCVE-2025-57348The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initialization, which could allow an attacker to inject properties into the prototype of built-in objects. This issue, categorized under CWE-1321, arises from improper validation of user-supplied input in the package's resource initialization process. Successful exploitation may lead to denia
- Affected
- <= 5.0.0-beta.19
- Fixed in
- not stated
- Weakness
- CWE-1321
- Published
- 2025-09-24
- Source
- github