CVE-2025-57347

Source
https://cve.org/CVERecord?id=CVE-2025-57347
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57347.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-57347
Published
2025-09-24T00:00:00Z
Modified
2026-08-12T03:51:17.692021312Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability exists in the 'dagre-d3-es' Node.js package version 7.0.9, specifically within the 'bk' module's addConflict function, which fails to properly sanitize user-supplied input during property assignment operations. This flaw allows attackers to exploit prototype pollution vulnerabilities by injecting malicious input values (e.g., "proto"), enabling unauthorized modification of the JavaScript Object prototype chain. Successful exploitation could lead to denial of service conditions, unexpected application behavior, or potential execution of arbitrary code in contexts where polluted properties are later accessed or executed. The issue affects versions prior to 7.0.11 and remains unpatched at the time of disclosure.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57347.json"
}
References

Affected packages

Git / github.com/tbo47/dagre-es

Affected ranges

Type
GIT
Repo
https://github.com/tbo47/dagre-es
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "7.0.9"
        },
        {
            "last_affected": "7.0.9"
        }
    ],
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:tbo47:dagre-d3-es:7.0.9:*:*:*:*:node.js:*:*"
}

Affected versions

7.*
7.0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57347.json"