Vulnerability Description
billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Naver | Billboard.Js | < 3.15.1 |
Related Weaknesses (CWE)
References
- https://cve.naver.com/detail/cve-2025-49223.htmlVendor Advisory
FAQ
What is CVE-2025-49223?
CVE-2025-49223 is a vulnerability with a CVSS score of 9.8 (CRITICAL). billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injec...
How severe is CVE-2025-49223?
CVE-2025-49223 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-49223?
Check the references section above for vendor advisories and patch information. Affected products include: Naver Billboard.Js.