CVE-2025-64718Medium· 5.3▾ Sunlitjs-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (__proto__). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1 and 3.14.2. Users can protect against this kind of attack on the server by using node --disable-proto=delete or deno (in Deno, pollution protection is on by default).
js-yaml < 3.14.2js-yaml >= 4.0.0, < 4.1.1Upgrade past the affected range:
js-yaml 4.1.1Connected by shared product, vendor, weakness, or advisory.
GHSA-r3ph-w7gj-g6xmMedium· 5.3js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
CVE-2026-84375High· 7.5js-yaml is a JavaScript YAML parser and dumper
GHSA-5p4m-2wfm-xmqjHigh· 7.5JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
GHSA-pm4m-ph32-ghv5High· 7.5js-yaml: Exponential parsing time in flow collections leads to denial of service
CVE-2026-59870High· 7.5js-yaml is a JavaScript YAML parser and dumper
CVE-2026-59869High· 7.5js-yaml is a JavaScript YAML parser and dumper