CVE-2025-57321

CRITICAL

Magix-combine-ex < 1.2.10 - Prototype Pollution

Title source: rule
STIX 2.1

Description

A Prototype Pollution vulnerability in the util-deps.addFileDepend function of magix-combine-ex versions thru 1.2.10 allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

Scores

CVSS v3 9.8
EPSS 0.0014
EPSS Percentile 33.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-1321
Status published
Products (2)
magix-combine-ex_project/magix-combine-ex < 1.2.10
npm/magix-combine-ex 0npm
Published Sep 24, 2025
Tracked Since Feb 18, 2026