PT-2025-39315 · Csvtojson · Csvtojson

CVE-2025-57350

·

Published

2025-09-24

·

Updated

2025-10-17

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions csvtojson versions prior to 2.0.10
Description The csvtojson package has a flaw due to inadequate sanitization of nested header names during parsing. Processing CSV input with crafted header fields referencing prototype chains (like using proto) can unintentionally modify the base Object prototype. This can cause denial of service or unexpected behavior, especially when processing untrusted CSV data. The issue does not require user interaction beyond providing a malicious CSV file. The vulnerable component is parser jsonarray.
Recommendations Update to version 2.0.10 or later.

Exploit

Fix

DoS

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-57350
GHSA-VRW9-G62V-7FMF

Affected Products

Csvtojson