Vulnerabilities/

messageformat prototype pollution vulnerability

Severity:
Medium

Description

The Runtime components of messageformat package for Node.js version 3.0.1 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the processing of message data, an attacker can manipulate the prototype chain of JavaScript objects by providing specially crafted input.

Recommendation

Update the @messageformat/runtime package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@messageformat/runtime
Anything's wrong? Let us know Last updated on October 31, 2025