8.8
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
Description
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Linkify (linkifyjs) allows XSS Targeting HTML Attributes and Manipulating User-Controlled Variables.This issue affects Linkify: from 4.3.1 before 4.3.2.
Basic Information
ID
CVE-2025-8101
Source
Fluid Attacks
Published
Jul 25, 2025 at 21:52
Modified
Jul 28, 2025 at 14:56
Affected Product
Vendor
Linkify
Product
Linkify
Version
4.3.1
Affected Versions
Linkify Linkify 4.3.1