PT-2025-39316 · Unknown+1 · Min-Document+1

Published

2025-09-24

·

Updated

2025-09-25

·

CVE-2025-57352

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions min-document versions prior to 2.19.0
Description A flaw exists in the 'min-document' package due to improper handling of namespace operations within the removeAttributeNS function. An attacker can exploit this by manipulating the prototype chain of JavaScript objects through malicious input involving the proto property. This manipulation can lead to denial of service or arbitrary code execution, resulting from insufficient validation of attribute namespace removal operations and allowing unintended modification of critical object prototypes.
Recommendations Update to version 2.19.0 or later.

Exploit

Fix

DoS

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2025-57352
GHSA-RX8G-88G5-QH64

Affected Products

Debian
Min-Document