---
id: CVE-2025-64718
title: js-yaml is a JavaScript YAML parser and dumper
summary: >-
  js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and
  3.14.2, it's possible for an attacker to modify the prototype of the result of
  a parsed yaml document via prototype pollution (`__proto__`). All users who
  parse …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-1321
vendor: nodeca
product: js-yaml
affected:
  - js-yaml < 3.14.2
  - 'js-yaml >= 4.0.0, < 4.1.1'
patched:
  - js-yaml 4.1.1
published: '2025-11-13'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64718'
references:
  - url: >-
      https://github.com/nodeca/js-yaml/commit/383665ff4248ec2192d1274e934462bb30426879
    label: security-advisories@github.com
  - url: >-
      https://github.com/nodeca/js-yaml/commit/5278870a17454fe8621dbd8c445c412529525266
    label: security-advisories@github.com
  - url: 'https://github.com/nodeca/js-yaml/issues/730#issuecomment-3549635876'
    label: security-advisories@github.com
  - url: 'https://github.com/nodeca/js-yaml/security/advisories/GHSA-mh29-5h37-fv8m'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-mh29-5h37-fv8m'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00408
epssPercentile: 0.32928
ingestedAt: '2026-10-07T21:54:15.033Z'
---

## Overview

js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1 and 3.14.2. Users can protect against this kind of attack on the server by using `node --disable-proto=delete` or `deno` (in Deno, pollution protection is on by default).

## Affected

- `js-yaml < 3.14.2`
- `js-yaml >= 4.0.0, < 4.1.1`

## Remediation

Upgrade past the affected range:

- `js-yaml 4.1.1`
