PT-2025-39336 · Spmrc · Spmrc

Published

2025-09-24

·

Updated

2025-10-20

·

CVE-2025-57327

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions spmrc versions prior to 1.2.0
Description spmrc is a package that provides the rc manager for spm. A Prototype Pollution vulnerability exists in the set and config functions. This allows attackers to inject properties on Object.prototype by supplying a crafted payload. This can lead to a denial of service (DoS).
Recommendations Update spmrc to version 1.2.0 or later.

Exploit

Fix

DoS

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2025-57327
GHSA-R2RV-8PP3-65XW

Affected Products

Spmrc