6.5

CVE-2025-57348

The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initialization, which could allow an attacker to inject properties into the prototype of built-in objects. This issue, categorized under CWE-1321, arises from improper validation of user-supplied input in the package's resource initialization process. Successful exploitation may lead to denial of service or arbitrary code execution in affected environments. The vulnerability affects versions up to and including 5.0.0-beta.19, and no official fix has been released to date.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Node-cube ≫ Node-cube SwPlatform node.js Version < 5.0.0
Node-cube ≫ Node-cube Version 5.0.0 Update beta0 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta1 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta10 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta11 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta12 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta13 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta14 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta15 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta16 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta17 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta18 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta19 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta2 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta3 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta4 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta5 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta6 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta8 SwPlatform node.js
Node-cube ≫ Node-cube Version 5.0.0 Update beta9 SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.298
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

https://github.com/VulnSageAgent/PoCs/tree/main/JavaScript/prototype-pollution/CVE-2025-57348
Third Party Advisory
https://github.com/node-cube/cube/issues/153
Third Party Advisory