High severityNVD Advisory· Published Sep 25, 2025· Updated Sep 25, 2025
CVE-2025-57317
CVE-2025-57317
Description
apidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulnerability in the preProcess function of apidoc-core versions thru 0.15.0 allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apidoc-corenpm | <= 0.15.0 | — |
Affected products
2- apidoc-core/apidoc-coredescription
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-5q53-78f2-6gf8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-57317ghsaADVISORY
- github.com/OrangeShieldInfos/PoCs/tree/main/JavaScript/prototype-pollution/CVE-2025-57317ghsaWEB
- github.com/VulnSageAgent/PoCs/blob/main/JavaScript/prototype-pollution/apidoc-core%400.15.0/index.jsghsaWEB
News mentions
0No linked articles in our index yet.