VYPR

npm package

apidoc-core

pkg:npm/apidoc-core

Vulnerabilities (2)

  • CVE-2025-13158CriDec 26, 2025
    affected >= 0.2.0, <= 0.15.0

    Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to modify JavaScript object prototypes via malformed data structures, including the “define” property processed by the application, potentially leading to denial of

  • CVE-2025-57317Sep 25, 2025
    affected <= 0.15.0

    apidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulnerability in the preProcess function of apidoc-core versions thru 0.15.0 allows attackers to inject properties on Object.prototype via supplying a crafted payload