Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Linkify (linkifyjs) allows XSS Targeting HTML Attributes and Manipulating User-Controlled Variables.This issue affects Linkify: from 4.3.1 before 4.3.2.
{
"github_reviewed": true,
"github_reviewed_at": "2025-07-29T19:09:33Z",
"severity": "HIGH",
"nvd_published_at": "2025-07-25T22:15:25Z",
"cwe_ids": [
"CWE-1321"
]
}