CVE-2025-68130

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-68130
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68130.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-68130
Aliases
Related
Published
2025-12-16T16:50:42.542Z
Modified
2025-12-23T23:58:30.232995Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L CVSS Calculator
Summary
tRPC has possible prototype pollution in `experimental_nextAppDirCaller`
Details

tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27.0 and prior to versions 10.45.3 and 11.8.0, a A prototype pollution vulnerability exists in @trpc/server's formDataToObject function, which is used by the Next.js App Router adapter. An attacker can pollute Object.prototype by submitting specially crafted FormData field names, potentially leading to authorization bypass, denial of service, or other security impacts. Note that this vulnerability is only present when using experimental_caller / experimental_nextAppDirCaller. Versions 10.45.3 and 11.8.0 fix the issue.

Database specific
{
    "cwe_ids": [
        "CWE-1321"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68130.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/trpc/trpc

Affected ranges

Type
GIT
Repo
https://github.com/trpc/trpc
Events
Database specific
{
    "versions": [
        {
            "introduced": "10.27.0"
        },
        {
            "fixed": "10.45.3"
        }
    ]
}
Type
GIT
Repo
https://github.com/trpc/trpc
Events
Database specific
{
    "versions": [
        {
            "introduced": "11.0.0"
        },
        {
            "fixed": "11.8.0"
        }
    ]
}

Affected versions

v10.*

v10.27.0
v10.27.1
v10.27.2
v10.27.3
v10.28.0
v10.28.1
v10.28.2
v10.29.0
v10.29.1
v10.30.0
v10.31.0
v10.32.0
v10.33.0
v10.33.1
v10.34.0
v10.34.1
v10.35.0
v10.36.0
v10.37.0
v10.37.1
v10.38.0
v10.38.1
v10.38.2
v10.38.3
v10.38.4
v10.38.5
v10.39.0
v10.40.0
v10.41.0
v10.42.0
v10.43.0
v10.43.1
v10.43.2
v10.43.3
v10.43.4
v10.43.5
v10.43.6
v10.43.7
v10.44.0
v10.44.1
v10.45.0
v10.45.1
v10.45.2

v11.*

v11.0.0
v11.0.1
v11.0.2
v11.0.3
v11.0.4
v11.1.0
v11.1.1
v11.1.2
v11.1.3
v11.1.4
v11.2.0
v11.3.0
v11.3.1
v11.4.0
v11.4.1
v11.4.2
v11.4.3
v11.4.4
v11.5.0
v11.5.1
v11.6.0
v11.7.0
v11.7.1
v11.7.2

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68130.json"