CVE-2025-8101

ADVISORY - github

Summary

Prototype Pollution in internal assign() helper in Linkify allows remote attackers to execute arbitrary JavaScript (Stored or Reflected XSS) via injection of event handlers through unfiltered proto property. This issue affects Linkify version 4.3.1 and is fixed in 4.3.2.

EPSS Score: 0.00501 (0.397)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

ADVISORY - github

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

ADVISORY - redhat

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')


NIST

CREATED

UPDATED

ADVISORY IDCVE-2025-8101
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

8.8high

GitHub

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

8.8high

Red Hat

CREATED

UPDATED

ADVISORY IDCVE-2025-8101
EXPLOITABILITY SCORE

3.9

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

8.6high

Chainguard

CREATED

UPDATED

ADVISORY ID

CGA-3f3j-3r3w-2fj9

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY