Vulnerabilities (CVE)

Filtered by vendor Web3js Subscribe
Filtered by product Web3-core-subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-57330 1 Web3js 1 Web3-core-subscriptions 2025-10-17 N/A 7.5 HIGH
The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in the attachToObject function of web3-core-subscriptions version 1.10.4 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.