Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22758 | Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS) |
Github GHSA |
GHSA-95jq-xph2-cx9h | Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS) |
Wed, 03 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:linkify:linkify:*:*:*:*:*:*:*:* |
Tue, 29 Jul 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 28 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 26 Jul 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linkify
Linkify linkify |
|
| Vendors & Products |
Linkify
Linkify linkify |
Fri, 25 Jul 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Linkify (linkifyjs) allows XSS Targeting HTML Attributes and Manipulating User-Controlled Variables.This issue affects Linkify: from 4.3.1 before 4.3.2. | |
| Title | Linkify 4.3.1 - Prototype Pollution & HTML Attribute Injection (XSS) | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2025-12-03T21:04:19.184Z
Reserved: 2025-07-23T20:18:23.797Z
Link: CVE-2025-8101
Updated: 2025-07-28T14:56:33.311Z
Status : Deferred
Published: 2025-07-25T22:15:25.620
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-8101
OpenCVE Enrichment
Updated: 2025-07-26T11:55:07Z
EUVD
Github GHSA