Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xcg2-9pp4-j82x | rollbar vulnerable to Prototype Pollution in merge() |
Fri, 24 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rollbar
Rollbar rollbar |
|
| Vendors & Products |
Rollbar
Rollbar rollbar |
Thu, 23 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Oct 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rollbar.js offers error tracking and logging from Javascript to Rollbar. In versions before 2.26.5 and from 3.0.0-alpha1 to before 3.0.0-beta5, there is a prototype pollution vulnerability in merge(). If application code calls rollbar.configure() with untrusted input, prototype pollution is possible. This issue has been fixed in versions 2.26.5 and 3.0.0-beta5. A workaround involves ensuring that values passed to rollbar.configure() do not contain untrusted input. | |
| Title | Rollbar.js Prototype Pollution Vulnerability in merge() | |
| Weaknesses | CWE-1321 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-23T20:16:08.104Z
Reserved: 2025-10-15T15:03:28.134Z
Link: CVE-2025-62517
Updated: 2025-10-23T20:13:59.361Z
Status : Deferred
Published: 2025-10-23T20:15:41.057
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-62517
No data.
OpenCVE Enrichment
Updated: 2025-10-24T10:16:39Z
Github GHSA