CVE-2025-3197
CVSS 3.1 Score 7.3 of 10 (high)
Details
Summary
CVE-2025-3197 identifies a vulnerability in the expand-object package, specifically versions prior to 0.0.1. This issue arises from the expand() function in index.js, which expands a given string into an object. The function fails to check provided keys for sensitive properties such as __proto__, leading to a Prototype Pollution vulnerability. Attackers can exploit this flaw to modify the object's prototype, potentially leading to unintended behavior, data leakage, or even remote code execution. It is recommended that users update to the latest version of expand-object to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.