Critical
Low
Medium
CVE-2025-57349
Overview
The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message key paths in versions prior to 2.3.0. The flaw arises when processing nested message keys containing special characters (...
Critical
Low
Medium
No items found.