CVE-2025-3197 - Apache expand-object Prototype Pollution
CVE ID : CVE-2025-3197
Published : April 4, 2025, 5:15 a.m. | 1 hour, 17 minutes ago
Description : Versions of the package expand-object from 0.0.0 are vulnerable to Prototype Pollution in the expand() function in index.js. This function expands the given string into an object and allows a nested property to be set without checking the provided keys for sensitive properties like __proto__.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : April 4, 2025, 5:15 a.m. | 1 hour, 17 minutes ago
Description : Versions of the package expand-object from 0.0.0 are vulnerable to Prototype Pollution in the expand() function in index.js. This function expands the given string into an object and allows a nested property to be set without checking the provided keys for sensitive properties like __proto__.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...