High severity7.5NVD Advisory· Published Sep 24, 2025· Updated Jun 17, 2026
CVE-2025-57318
CVE-2025-57318
Description
A Prototype Pollution vulnerability in the toCsv function of csvjson versions thru 5.1.0 allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
csvjsonnpm | <= 5.1.0 | — |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/VulnSageAgent/PoCs/tree/main/JavaScript/prototype-pollution/CVE-2025-57318nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-xq4f-3jxp-qv6mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-57318ghsaADVISORY
- github.com/VulnSageAgent/PoCs/blob/main/JavaScript/prototype-pollution/csvjson%405.1.0/index.jsnvdBroken LinkWEB
News mentions
0No linked articles in our index yet.