← Back

CVE-2025-57348

nvd nist
Published: Sep 24, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Exploitability: 3.9 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initialization, which could allow an attacker to inject properties into the prototype of built-in objects. This issue, categorized under CWE-1321, arises from improper validation of user-supplied input in the package's resource initialization process. Successful exploitation may lead to denial of service or arbitrary code execution in affected environments. The vulnerability affects versions up to and including 5.0.0-beta.19, and no official fix has been released to date.

Affected (20)

Products: Node Cube: Node Cube
1 product
Node Cube
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Node Cube
Before 5.0.0
Version 5.0.0 beta0
Version 5.0.0 beta10
Version 5.0.0 beta11
Version 5.0.0 beta12
Version 5.0.0 beta13
Version 5.0.0 beta14
Version 5.0.0 beta15
Version 5.0.0 beta16
Version 5.0.0 beta17
Version 5.0.0 beta18
Version 5.0.0 beta19
Version 5.0.0 beta1
Version 5.0.0 beta2
Version 5.0.0 beta3
Version 5.0.0 beta4
Version 5.0.0 beta5
Version 5.0.0 beta6
Version 5.0.0 beta8
Version 5.0.0 beta9

References (2)

Timeline

No history available yet.