CVE-2025-49223: Critical severity billboard.js vulnerability
billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49223?
CVE-2025-49223 is classified as a high severity vulnerability due to its potential for arbitrary code execution and Denial of Service attacks.
How do I fix CVE-2025-49223?
To fix CVE-2025-49223, update your billboard.js library to version 3.15.1 or later.
What impact does CVE-2025-49223 have on my project?
CVE-2025-49223 can allow attackers to inject arbitrary properties, leading to system compromise or service disruption.
Is CVE-2025-49223 present in earlier versions of billboard.js?
Yes, CVE-2025-49223 affects all versions of billboard.js prior to 3.15.1.
How can I identify if my application is vulnerable to CVE-2025-49223?
Check your application's dependencies for billboard.js versions below 3.15.1 to determine vulnerability to CVE-2025-49223.