Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10037 | estree-util-value-to-estree allows prototype pollution in generated ESTree |
Github GHSA |
GHSA-f7f6-9jq7-3rqj | estree-util-value-to-estree allows prototype pollution in generated ESTree |
Mon, 07 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Apr 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed in 3.3.3. | |
| Title | estree-util-value-to-estree allows prototype pollution in generated ESTree | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-07T15:45:04.415Z
Reserved: 2025-04-01T21:57:32.953Z
Link: CVE-2025-32014
Updated: 2025-04-07T15:37:53.960Z
Status : Deferred
Published: 2025-04-07T15:15:44.593
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-32014
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA