Low severityNVD Advisory· Published Sep 24, 2025· Updated Sep 26, 2025
CVE-2025-57326
CVE-2025-57326
Description
A Prototype Pollution vulnerability in the byGroupAndType function of sassdoc-extras v2.5.1 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sassdoc-extrasnpm | <= 3.0.0 | — |
Affected products
2- sassdoc-extras/sassdoc-extrasdescription
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-3mpm-jx38-9m8wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-57326ghsaADVISORY
- github.com/VulnSageAgent/PoCs/blob/main/JavaScript/prototype-pollution/sassdoc-extras%402.5.1/index.jsghsaWEB
- github.com/VulnSageAgent/PoCs/tree/main/JavaScript/prototype-pollution/CVE-2025-57326ghsaWEB
News mentions
0No linked articles in our index yet.