216.73.217.22

CVE-2025-55164

· Published 12/08/2025 16:15 · Modified 13/08/2025 17:34

Labels: CVE-2025-55164 2025-08-12CVE-2025-55164CWE-1321[email protected]

Essential information

Published
12/08/2025 16:15
Modified
13/08/2025 17:34
Author
Creator
CVSS
8.8 HIGH (v3) 8.8 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

content-security-policy-parser parses content security policy directives. A prototype pollution vulnerability exists in versions 0.5.0 and earlier, wherein if a policy name is called __proto__, one can override the Object prototype. This issue has been patched in version 0.6.0. A workaround involves disabling prototype method in NodeJS, neutralizing all possible prototype pollution attacks. Provide either --disable-proto=delete (recommended) or --disable-proto=throw as an argument to node to enable this feature.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
content-security-policy-parser / content-security-policy-parser cpe:2.3:a:content-security-policy-parser:content-security-policy-parser:<0.6.0:*:*:*:*:*:*:*

References