Description
The Runtime components of messageformat package for Node.js version 3.0.1 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the processing of message data, an attacker can manipulate the prototype chain of JavaScript objects by providing specially crafted input.
Recommendation
Update the @messageformat/runtime package to the latest compatible version. Followings are version details:
- Affected version(s): = 3.0.1
- Patched version(s): 3.0.2
References
Could your website be exposed too?
SmartScanner can check your website for messageformat prototype pollution vulnerability and gives you actionable findings to investigate.
Start a free scanRelated Issues
- messageformat has a prototype pollution vulnerability - CVE-2025-57349
- ts-fns has prototype pollution vulnerability - CVE-2025-57351
- content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE - CVE-2025-55164
- Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions - CVE-2025-13465


