Description
json-schema before version 0.4.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’).
Recommendation
Update the json-schema package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.4.0
- Patched version(s): 0.4.0
References
Could your website be exposed too?
SmartScanner can check your website for json-schema is vulnerable to Prototype Pollution and gives you actionable findings to investigate.
Start a free scanRelated Issues
- json-schema-editor-visual vulnerable to prototype pollution - CVE-2025-57320
- MrSwitch hello.js vulnerable to prototype pollution - CVE-2021-26505
- jszip Vulnerable to Prototype Pollution - CVE-2021-23413
- npm package rfc6902 vulnerable to Prototype Pollution - CVE-2021-4245
You might also like:
See something that needs correcting? Let us knowUpdated January 17, 2025


