PT-2025-39322 · Npm · Dagre-D3-Es
Published
2025-09-24
·
Updated
2025-10-17
·
CVE-2025-57347
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
dagre-d3-es versions prior to 7.0.11
Description
A flaw exists in the 'dagre-d3-es' Node.js package within the 'bk' module’s
addConflict() function. The issue stems from inadequate input sanitization during property assignment, allowing prototype pollution. Attackers can inject malicious input values, such as proto, to modify the JavaScript Object prototype chain. Successful exploitation may result in denial of service, unexpected application behavior, or arbitrary code execution when polluted properties are accessed or executed.Recommendations
Update to dagre-d3-es version 7.0.11 or later.
Exploit
Fix
DoS
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dagre-D3-Es