216.73.217.22

CVE-2025-66456

· Published 09/12/2025 20:15 · Modified 17/12/2025 14:30

Labels: CVE-2025-66456 2025-12-09CVE-2025-66456CWE-1321[email protected]

Essential information

Published
09/12/2025 20:15
Modified
17/12/2025 14:30
Author
Creator
CVSS
9.1 CRITICAL (v3) 9.1 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 through 1.4.16 contain a prototype pollution vulnerability in `mergeDeep` after merging results of two standard schema validations with the same key. Due to the ordering of merging, there must be an any type that is set as a standalone guard, to allow for the `__proto__ prop` to be merged. When combined with GHSA-8vch-m3f4-q8jf this allows for a full RCE by an attacker. This issue is fixed in version 1.4.17. To workaround, remove the `__proto__ key` from body.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
elysiajs / elysia cpe:2.3:a:elysiajs:elysia:*:*:*:*:*:node.js:*:*

References