Description
json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setData and deleteData function of json-schema-editor-visual versions thru 1.1.1 allows attackers to inject or delete properties on Object.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.0.0
References
Related Issues
- Elysia vulnerable to prototype pollution with multiple standalone schema validation - CVE-2025-66456
- json-schema is vulnerable to Prototype Pollution - CVE-2021-3918
- algoliasearch-helper is vulnerable to Prototype Pollution in _merge() - CVE-2025-3193
- @pdfme/common vulnerable to to XSS and Prototype Pollution through its expression evaluation - CVE-2025-53626
You might also like:
- Tags:
- npm
- json-schema-editor-visual
Anything's wrong? Let us know Last updated on September 26, 2025


