Skip to content

fix prototype pollution in merge (<<)#731

Merged
puzrin merged 1 commit intonodeca:v3from
mhassan1:v3-fix-cve-2025-64718
Nov 14, 2025
Merged

fix prototype pollution in merge (<<)#731
puzrin merged 1 commit intonodeca:v3from
mhassan1:v3-fix-cve-2025-64718

Conversation

@mhassan1
Copy link
Copy Markdown

@mhassan1 mhassan1 commented Nov 14, 2025

This PR backports 383665f to v3.

Resolves #730.

@puzrin puzrin merged commit 5278870 into nodeca:v3 Nov 14, 2025
smfeest added a commit to smfeest/buttercup that referenced this pull request Nov 17, 2025
This is to address CVE-2025-64718 which is fixed in version 3.14.2 [1]
and 4.1.1 [2] of js-yaml.

[1] nodeca/js-yaml#731
[2] nodeca/js-yaml@383665f
smfeest added a commit to smfeest/buttercup that referenced this pull request Nov 18, 2025
This is to address CVE-2025-64718 which is fixed in version 3.14.2 [1]
and 4.1.1 [2] of js-yaml.

[1] nodeca/js-yaml#731
[2] nodeca/js-yaml@383665f
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants