PT-2025-22960 · Radashi · Radashi

Arkark

·

Published

2025-05-27

·

Updated

2025-05-27

·

CVE-2025-48054

CVSS v4.0

6.8

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions Radashi versions prior to 12.5.1
Description Radashi is a TypeScript utility toolkit. The set function within the Radashi library is vulnerable to prototype pollution. If an attacker can control parts of the path argument to the set function, they could potentially modify the prototype of all objects in the JavaScript runtime, leading to unexpected behavior, denial of service, or even remote code execution in some specific scenarios.
Recommendations For versions prior to 12.5.1, update to version 12.5.1 or later to resolve the issue. As a temporary workaround, consider sanitizing the path argument provided to the set function to ensure that no part of the path string is proto, prototype, or constructor.

Exploit

Fix

DoS

RCE

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2025-48054
GHSA-2XV9-GHH9-XC69

Affected Products

Radashi