Description
The Runtime components of messageformat package for Node.js version 3.0.1 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the processing of message data, an attacker can manipulate the prototype chain of JavaScript objects by providing specially crafted input.
Recommendation
Update the @messageformat/runtime package to the latest compatible version. Followings are version details:
- Affected version(s): = 3.0.1
- Patched version(s): 3.0.2
References
Related Issues
- messageformat has a prototype pollution vulnerability - CVE-2025-57349
- ts-fns has prototype pollution vulnerability - CVE-2025-57351
- content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE - CVE-2025-55164
- Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions - CVE-2025-13465
You might also like:
- Tags:
- npm
- @messageformat/runtime
Anything's wrong? Let us know Last updated on October 31, 2025


