Prototype Pollution Vulnerability in Node.js Messageformat Package
CVE-2025-57353
What is CVE-2025-57353?
The messageformat package for Node.js prior to version 3.0.1 is susceptible to a prototype pollution vulnerability due to inadequate validation of nested message keys. This flaw allows attackers to craft malicious input that can manipulate the prototype chain of JavaScript objects. By exploiting this vulnerability, an attacker can inject arbitrary properties into the Object.prototype, which may lead to unexpected application behavior or denial of service conditions throughout the application's lifecycle. This critical issue has yet to be addressed in the current version.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
