A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious input involving the __proto__ property, an attacker can manipulate the prototype chain of JavaScript objects, leading to denial of service or arbitrary code execution. This issue arises from insufficient validation of attribute namespace removal operations, allowing unintended modification of critical object prototypes. The vulnerability remains unaddressed in the latest available version.
History

Sat, 27 Sep 2025 00:15:00 +0000

Type Values Removed Values Added
Title min-document: min-document prototype pollution
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 25 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1321
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious input involving the __proto__ property, an attacker can manipulate the prototype chain of JavaScript objects, leading to denial of service or arbitrary code execution. This issue arises from insufficient validation of attribute namespace removal operations, allowing unintended modification of critical object prototypes. The vulnerability remains unaddressed in the latest available version.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-09-24T00:00:00.000Z

Updated: 2025-09-25T18:25:21.651Z

Reserved: 2025-08-17T00:00:00.000Z

Link: CVE-2025-57352

cve-icon Vulnrichment

Updated: 2025-09-25T18:25:16.323Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-24T18:15:41.637

Modified: 2025-09-26T14:32:53.583

Link: CVE-2025-57352

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-09-24T00:00:00Z

Links: CVE-2025-57352 - Bugzilla