PT-2025-39324 · Ts-Fns · Ts-Fns
Published
2025-09-24
·
Updated
2025-09-24
·
CVE-2025-57351
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
ts-fns versions prior to 13.0.7
Description
A prototype pollution issue exists due to inadequate validation of user-supplied keys within the
assign function. This allows manipulation of the Object.prototype chain. Attackers can inject arbitrary properties into the global object's prototype, potentially causing application crashes, unexpected code execution, or bypassing security checks that rely on prototype integrity. The root cause is improper handling of deep property assignment operations within the library’s public API functions.Recommendations
Update to version 13.0.7 or later.
Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ts-Fns