CVE-2025-64718
ADVISORY - githubSummary
Impact
In js-yaml 4.1.0, 4.0.0, and 3.14.1 and below, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (__proto__). All users who parse untrusted yaml documents may be impacted.
Patches
Problem is patched in js-yaml 4.1.1 and 3.14.2.
Workarounds
You can protect against this kind of attack on the server by using node --disable-proto=delete or deno (in Deno, pollution protection is on by default).
References
https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html
Common Weakness Enumeration (CWE)
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
NIST
3.9
CVSS SCORE
5.3mediumGitHub
3.9
CVSS SCORE
5.3mediumDebian
-
Ubuntu
-
CVSS SCORE
N/AmediumRed Hat
3.9
CVSS SCORE
5.3mediumChainguard
CGA-2gw8-7rqg-gw8r
-
Chainguard
CGA-2p9v-jvc4-8xq7
-
Chainguard
CGA-2qv7-7mjf-6qmw
-
Chainguard
CGA-356v-grqc-f4xw
-
Chainguard
CGA-3c6r-4ghv-m28h
-
Chainguard
CGA-598p-7cqw-86f3
-
Chainguard
CGA-5f7j-2v83-85p9
-
Chainguard
CGA-7hwv-hjqx-7j42
-
Chainguard
CGA-7jj2-7wc7-3hmr
-
Chainguard
CGA-82rp-46cx-873m
-
Chainguard
CGA-83wr-xg45-g79x
-
Chainguard
CGA-8456-788m-9x6m
-
Chainguard
CGA-8hr3-fm83-v7w8
-
Chainguard
CGA-9286-xp7f-hqpm
-
Chainguard
CGA-9q79-rp22-6vqh
-
Chainguard
CGA-c8pw-7wq5-cv4q
-
Chainguard
CGA-c96m-f889-7vc3
-
Chainguard
CGA-f6p7-c6p7-p6cv
-
Chainguard
CGA-fm89-ccr4-3f6c
-
Chainguard
CGA-g7q7-7jv6-g4g8
-
Chainguard
CGA-hpw3-929h-f755
-
Chainguard
CGA-j6vx-8w9h-29w2
-
Chainguard
CGA-jfhr-7q72-p4j6
-
Chainguard
CGA-jq76-f948-q8rw
-
Chainguard
CGA-m8q5-hgg3-7vj7
-
Chainguard
CGA-mfcv-6pv8-6v39
-
Chainguard
CGA-mxm9-hxqf-pr7j
-
Chainguard
CGA-mxwc-5wc4-g7gh
-
Chainguard
CGA-ph77-h297-cjr7
-
Chainguard
CGA-prcr-hj45-x4jp
-
Chainguard
CGA-q9xc-89g3-cm2h
-
Chainguard
CGA-vm9v-229q-27rh
-
Chainguard
CGA-x6wh-jhch-gcj7
-
Chainguard
CGA-x77q-p25m-4x2p
-
Chainguard
CGA-xcp6-3g7h-pmpx
-
minimos
MINI-4w3g-4w2v-9524
-
minimos
MINI-5v8w-pgcp-2wq4
-
minimos
MINI-5w96-f692-8x63
-
minimos
MINI-6v2c-wfc7-5vg2
-
minimos
MINI-8jwx-793q-2wmj
-
minimos
MINI-cfgf-wxx6-7gf5
-
minimos
MINI-chr3-jmjh-fvmf
-
minimos
MINI-gcw7-2c9r-9gww
-
minimos
MINI-hr46-j729-h59x
-
minimos
MINI-j8q6-vwm3-qvqm
-
minimos
MINI-mp2j-7j26-62fq
-
minimos
MINI-q9qj-46c9-4grw
-
minimos
MINI-x2g7-j7f6-5rx9
-
minimos
MINI-x3vh-jxvc-chv9
-
minimos
MINI-x3vj-cmxh-ggc5
-
minimos
MINI-x9ww-qh25-h7g3
-
minimos
MINI-xwm2-xhhw-2w6h
-