Critical severity9.8NVD Advisory· Published Jan 3, 2024· Updated Jun 17, 2026
CVE-2023-46308
CVE-2023-46308
Description
In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
plotly/plotly.jsPackagist | < 2.25.2 | 2.25.2 |
plotly.jsnpm | < 2.25.2 | 2.25.2 |
Affected products
4- ghsa-coords2 versions
< 2.25.2+ 1 more
- (no CPE)range: < 2.25.2
- (no CPE)range: < 2.25.2
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-wjc4-73q6-gv3mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-46308ghsaADVISORY
- github.com/plotly/plotly.R/issues/2463nvdWEB
- github.com/plotly/plotly.js/commit/02498404c8ad7a3395191e65694fb142a37b0fe9ghsaWEB
- github.com/plotly/plotly.js/commit/5efd2a1f07a418b230a5626fc6c1c7929c47949dghsaWEB
- github.com/plotly/plotly.js/releases/tag/v2.25.2nvdRelease NotesWEB
- plotly.com/javascriptghsaWEB
- plotly.com/javascript/nvdProduct
News mentions
0No linked articles in our index yet.