CVE-2025-49223

CRITICAL9.8EPSS 0.83%

billboard.js allows prototype pollution via the function generate

Published: 6/4/2025Modified: 7/29/2025
Also known as:GHSA-65p9-j6pg-72hj

Description

billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (6)