Vulnerability Description
A Prototype Pollution vulnerability in the util-deps.addFileDepend function of magix-combine-ex versions thru 1.2.10 allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Magix-Combine-Ex Project | Magix-Combine-Ex | <= 1.2.10 |
Related Weaknesses (CWE)
References
- https://github.com/VulnSageAgent/PoCs/blob/main/JavaScript/prototype-pollution/mBroken Link
- https://github.com/VulnSageAgent/PoCs/tree/main/JavaScript/prototype-pollution/CThird Party Advisory
FAQ
What is CVE-2025-57321?
CVE-2025-57321 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A Prototype Pollution vulnerability in the util-deps.addFileDepend function of magix-combine-ex versions thru 1.2.10 allows attackers to inject properties on Object.prototype via supplying a crafted p...
How severe is CVE-2025-57321?
CVE-2025-57321 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-57321?
Check the references section above for vendor advisories and patch information. Affected products include: Magix-Combine-Ex Project Magix-Combine-Ex.