CVE-2025-13158None▾ SunlitPrototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to modify JavaScript object prototypes via malformed data structures, including the “define” property processed by the ap…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to modify JavaScript object prototypes via malformed data structures, including the “define” property processed by the application, potentially leading to denial of service or unintended behavior in applications relying on the integrity of prototype chains. This affects the preProcess() function in api_group.js, api_param_title.js, api_use.js, and api_permission.js worker modules.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
GHSA-3wcj-gjvf-fvchMedium· 4.8Duplicate Advisory: Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
CVE-2026-103036Medium· 6.5oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards
CVE-2026-103918Medium· 6.5oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards
CVE-2026-104849Critical· 9.5Tinypool is a minimal Node.js worker thread pool implementation
CVE-2026-104848Critical· 9.5Tinypool is a minimal Node.js worker thread pool implementation
CVE-2026-94646High· 8.7Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings. This issue affects Apach…