---
id: CVE-2025-13158
title: >-
  Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all
  subsequent versions allows remote attackers to modify JavaScript object
  prototypes via malformed data structures, including the “define” property
  processed by the ap…
summary: >-
  Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all
  subsequent versions allows remote attackers to modify JavaScript object
  prototypes via malformed data structures, including the “define” property
  processed by the ap…
severity: none
cwe:
  - CWE-1321
published: '2025-12-26'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:10:00.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13158'
references:
  - url: 'https://www.sonatype.com/security-advisories/cve-2025-13158'
    label: 103e4ec9-0a87-450b-af77-479448ddef11
tags:
  - nvd
epss: 0.00503
epssPercentile: 0.40906
ingestedAt: '2026-10-05T19:30:59.937Z'
---

## Overview

Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to modify JavaScript object prototypes via malformed data structures, including the “define” property processed by the application, potentially leading to denial of service or unintended behavior in applications relying on the integrity of prototype chains. This affects the preProcess() function in api_group.js, api_param_title.js, api_use.js, and api_permission.js worker modules.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
