CVE-2025-13158

Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to modify JavaScript object prototypes via malformed data structures, including the “define” property processed by the application, potentially leading to denial of service or unintended behavior in applications relying on the integrity of prototype chains. This affects the preProcess() function in api_group.js, api_param_title.js, api_use.js, and api_permission.js worker modules.
CVSS

No CVSS.

Configurations

No configuration.

History

26 Dec 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-26 16:15

Updated : 2025-12-29 15:57


NVD link : CVE-2025-13158

Mitre link : CVE-2025-13158

CVE.ORG link : CVE-2025-13158


JSON object : View

Products Affected

No product.

CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')