CVE-2025-57321 Details
Description
A Prototype Pollution vulnerability in the util-deps.addFileDepend function of magix-combine-ex versions thru 1.2.10 allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.
A prototype pollution vulnerability has been identified in the Node.js package 'magix-combine-ex' versions prior to and including 1.2.10. The issue arises in the 'util-deps' module, specifically within the 'addFileDepend' function, where user input is not properly sanitized. This vulnerability allows attackers to manipulate the 'riskyName' parameter to inject properties into the Object.prototype, affecting the prototype chain of objects handled by the module. The exploitation of this vulnerability can disrupt the application's normal functioning, causing a denial-of-service condition.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1321 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| magix-combine-ex project magix-combine-ex | <= 1.2.10 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 17, 2025 | Initial Analysis | [email protected] |
| Sep 26, 2025 | CVE Modified | CISA-ADP |
| Sep 24, 2025 | New CVE Received | [email protected] |