{"id":"CVE-2025-64718","aliases":["GHSA-mh29-5h37-fv8m"],"url":"https://o3.security/vulnerability/CVE-2025-64718","summary":"js-yaml has prototype pollution in merge (<<)","details":"js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1 and 3.14.2. Users can protect against this kind of attack on the server by using `node --disable-proto=delete` or `deno` (in Deno, pollution protection is on by default).","published":"2025-11-13T15:32:44.634Z","modified":"2026-07-15T01:49:22.089028736Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"js-yaml","fixedVersion":"4.1.1"},{"ecosystem":"npm","name":"js-yaml","fixedVersion":"3.14.2"}],"fix":{"url":"https://github.com/nodeca/js-yaml/commit/383665ff4248ec2192d1274e934462bb30426879","label":"nodeca/js-yaml@383665f"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64718.json"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mh29-5h37-fv8m"},{"type":"ADVISORY","url":"https://github.com/nodeca/js-yaml/security/advisories/GHSA-mh29-5h37-fv8m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64718"},{"type":"REPORT","url":"https://github.com/nodeca/js-yaml/issues/730#issuecomment-3549635876"},{"type":"FIX","url":"https://github.com/nodeca/js-yaml/commit/383665ff4248ec2192d1274e934462bb30426879"},{"type":"FIX","url":"https://github.com/nodeca/js-yaml/commit/5278870a17454fe8621dbd8c445c412529525266"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:22.089028736Z"}}