PT-2025-23732 · Unknown · Billboard.Js

Published

2025-06-03

·

Updated

2025-06-09

·

CVE-2025-49223

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions billboard.js versions prior to 3.15.1
Description The issue is related to a prototype pollution via the generate function, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) by injecting arbitrary properties.
Recommendations For versions prior to 3.15.1, update to version 3.15.1 or later to resolve the issue. As a temporary workaround, consider disabling the generate function until a patch is available.

Exploit

Fix

DoS

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05057
CVE-2025-49223
GHSA-65P9-J6PG-72HJ

Affected Products

Billboard.Js