High severity7.5NVD Advisory· Published Sep 24, 2025· Updated Jun 17, 2026
CVE-2025-57327
CVE-2025-57327
Description
spmrc is a package that provides the rc manager for spm. A Prototype Pollution vulnerability in the set and config function of spmrc version 1.2.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
spmrcnpm | <= 1.2.0 | — |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/VulnSageAgent/PoCs/tree/main/JavaScript/prototype-pollution/CVE-2025-57327nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-r2rv-8pp3-65xwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-57327ghsaADVISORY
- github.com/VulnSageAgent/PoCs/blob/main/JavaScript/prototype-pollution/spmrc%401.2.0/index.jsnvdBroken LinkWEB
News mentions
0No linked articles in our index yet.