Vulnerabilities/

plotly.js prototype pollution vulnerability

Severity:
High

Description

In Plotly plotly.js before 2.25.2, plot API calls have a risk of proto being polluted in expandObjectPaths or nestedProperty.

Recommendation

Update the plotly.js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
plotly.js
Anything's wrong? Let us know Last updated on December 26, 2025