PT-2024-13352 · Plotly · Plotly.Js

Published

2024-01-02

·

Updated

2025-12-24

·

CVE-2023-46308

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Plotly plotly.js versions prior to 2.25.2
Description The issue concerns plot API calls having a risk of proto being polluted in expandObjectPaths or nestedProperty. This could potentially lead to security issues, although specific details about the estimated number of affected devices or real-world incidents are not provided.
Recommendations For versions prior to 2.25.2, update to version 2.25.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the expandObjectPaths and nestedProperty functions until a patch is applied. Avoid using these functions in plot API calls until the issue is resolved.

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2023-46308
GHSA-WJC4-73Q6-GV3M
OPENSUSE-SU-2024:13607-1
RSEC-2025-1

Affected Products

Plotly.Js