CVE-2025-32014
estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed in 3.3.3.
Vendor
-
Product
-
CWE
Yayın Tarihi
2025-04-07 15:15:44
Güncelleme
2025-04-08 18:14:17
Source Identifier
security-advisories@github.com
KEV Date Added
-