PT-2025-18011 · Nortikin · Sverchok

Gavin Zhong

+1

·

Published

2025-04-27

·

Updated

2025-04-27

·

CVE-2025-3982

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions nortikin Sverchok version 1.3.0
Description A problematic issue was found in the function SvSetPropNodeMK2 of the file sverchok/nodes/object nodes/getsetprop mk2.py of the component Set Property Mk2 Node. This issue leads to improperly controlled modification of object prototype attributes, also known as 'prototype pollution'. The attack can be launched remotely. The exploit has been publicly disclosed.
Recommendations For nortikin Sverchok version 1.3.0, as a temporary workaround, consider disabling the SvSetPropNodeMK2 function until a patch is available. Restrict access to the Set Property Mk2 Node component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-3982

Affected Products

Sverchok