Description
billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Published: 2025-06-04
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-16802 billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Github GHSA Github GHSA GHSA-65p9-j6pg-72hj billboard.js allows prototype pollution via the function generate
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00229}

epss

{'score': 0.00081}


Fri, 06 Jun 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Naver
Naver billboard.js
CPEs cpe:2.3:a:naver:billboard.js:*:*:*:*:*:*:*:*
Vendors & Products Naver
Naver billboard.js

Wed, 04 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 04 Jun 2025 02:30:00 +0000

Type Values Removed Values Added
Description billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Weaknesses CWE-1321
References

Subscriptions

Naver Billboard.js
cve-icon MITRE

Status: PUBLISHED

Assigner: naver

Published:

Updated: 2025-06-04T13:33:44.239Z

Reserved: 2025-06-04T01:29:40.014Z

Link: CVE-2025-49223

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2025-06-04T03:15:27.190

Modified: 2025-06-06T19:30:16.060

Link: CVE-2025-49223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses