CVE-2025-13158 Details
Description
Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to modify JavaScript object prototypes via malformed data structures, including the “define” property processed by the application, potentially leading to denial of service or unintended behavior in applications relying on the integrity of prototype chains. This affects the preProcess() function in api_group.js, api_param_title.js, api_use.js, and api_permission.js worker modules.
A prototype pollution vulnerability exists in apidoc-core versions 0.2.0 and later. This vulnerability allows remote attackers to alter JavaScript object prototypes by sending malformed data structures. The 'define' property, which is processed by the application, can be targeted, potentially causing a denial of service or unintended behavior in applications that depend on the integrity of prototype chains. The vulnerability impacts the preProcess() function within the api_group.js, api_param_title.js, api_use.js, and api_permission.js worker modules.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 26, 2025CISA-ADP
Assessed Dec 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.sonatype.com/security-advisories/cve-2025-13158 | Sonatype | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1321 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | Sonatype |
Affected Products
| Product | Versions |
|---|---|
| apidoc-core | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Sonatype |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 26, 2025 | New CVE Received | Sonatype |
Volerion