Vue.js — CWE-1321

All FrameworksVue.jsCWE-1321

3 CVEs categorized as CWE-1321 — Prototype Pollution in Vue.js.

CVE-2025-27597HIGH2025
Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the gl…
CVE-2024-52810MEDIUM2024
@intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the glob…
CVE-2024-11628MEDIUM2024
In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.