CVE-2025-8101
ADVISORY - githubSummary
Prototype Pollution in internal assign() helper in Linkify allows remote attackers to execute arbitrary JavaScript (Stored or Reflected XSS) via injection of event handlers through unfiltered proto property. This issue affects Linkify version 4.3.1 and is fixed in 4.3.2.
EPSS Score: 0.00501 (0.397)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
ADVISORY - github
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
ADVISORY - redhat
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
NIST
CREATED
UPDATED
ADVISORY IDCVE-2025-8101
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
8.8highGitHub
CREATED
UPDATED
ADVISORY IDGHSA-95jq-xph2-cx9h
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
8.8highRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2025-8101
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
8.6highChainguard
CREATED
UPDATED
ADVISORY ID
CGA-3f3j-3r3w-2fj9
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-