GHSA-95jq-xph2-cx9hHigh
Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)
🔗 CVE IDs covered (1)
📋 Description
Prototype Pollution in internal assign() helper in Linkify allows remote attackers to execute arbitrary JavaScript (Stored or Reflected XSS) via injection of event handlers through unfiltered proto property. This issue affects Linkify version 4.3.1 and is fixed in 4.3.2.
🎯 Affected products1
- npm/linkifyjs:= 4.3.1
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2025-8101
- https://fluidattacks.com/advisories/charly
- https://github.com/nfrasser/linkifyjs
- https://github.com/nfrasser/linkifyjs/releases/tag/v4.3.2
- https://www.npmjs.com/package/linkifyjs
- https://caverav.cl/posts/linkify-xss/linkify-xss
- https://github.com/nfrasser/linkifyjs/commit/931d3e28b68951b8f898ea4d6504696346b485b0
- https://github.com/advisories/GHSA-95jq-xph2-cx9h