CVE-2025-57317

apidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulnerability in the preProcess function of apidoc-core versions thru 0.15.0 allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apidocjs:apidoc-core:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2025-09-25 14:15

Updated : 2025-10-16 15:49


NVD link : CVE-2025-57317

Mitre link : CVE-2025-57317

CVE.ORG link : CVE-2025-57317


JSON object : View

Products Affected

apidocjs

  • apidoc-core
CWE
CWE-400

Uncontrolled Resource Consumption