Back

MEDIUM

estree-util-value-to-estree allows prototype pollution in generated ESTree

Published Apr 7, 2025

Description

estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed in 3.3.3.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 7, 2025
Updated Apr 7, 2025
Reserved Apr 1, 2025
CISA Vulnrichment
Updated Apr 7, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-F7F6-9JQ7-3RQJ