CVE Vulnerabilities

CVE-2025-58280

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Published: Sep 05, 2025 | Modified: Sep 11, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Vulnerability of exposing object heap addresses in the Ark eTS module. Impact: Successful exploitation of this vulnerability may affect availability.

Weakness

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Affected Software

NameVendorStart VersionEnd Version
HarmonyosHuawei5.0.1 (including)5.0.1 (including)
HarmonyosHuawei5.1.0 (including)5.1.0 (including)

Potential Mitigations

References