GHSA-95jq-xph2-cx9hHigh

Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)

Published
July 26, 2025
Last Modified
June 26, 2026

🔗 CVE IDs covered (1)

📋 Description

Prototype Pollution in internal assign() helper in Linkify allows remote attackers to execute arbitrary JavaScript (Stored or Reflected XSS) via injection of event handlers through unfiltered proto property. This issue affects Linkify version 4.3.1 and is fixed in 4.3.2.

🎯 Affected products1

  • npm/linkifyjs:= 4.3.1

🔗 References (8)