PT-2025-15241 · Unknown · Estree-Util-Value-To-Estree

Published

2025-04-07

·

Updated

2025-04-08

·

CVE-2025-32014

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions estree-util-value-to-estree versions prior to 3.3.3
Description The issue arises when estree-util-value-to-estree converts a JavaScript value to an ESTree expression. Specifically, when generating an ESTree from a value with a property named proto, the function would generate an object that specifies a prototype instead.
Recommendations For versions prior to 3.3.3, update to version 3.3.3 to resolve the issue.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2025-32014
GHSA-F7F6-9JQ7-3RQJ

Affected Products

Estree-Util-Value-To-Estree