Description
Prototype pollution vulnerability in merge(). If application code calls rollbar.configure() with untrusted input, prototype pollution is possible.
Recommendation
Update the rollbar package to the latest compatible version. Followings are version details:
Affected version(s): **>= 3.0.0-alpha1, <= 3.0.0-beta4 <= 2.26.4** Patched version(s): **3.0.0-beta5 2.26.5**
References
Could your website be exposed too?
SmartScanner can check your website for rollbar vulnerable to Prototype Pollution in merge() and gives you actionable findings to investigate.
Start a free scanRelated Issues
- rollbar vulnerable to prototype pollution - CVE-2025-57325
- algoliasearch-helper is vulnerable to Prototype Pollution in _merge() - CVE-2025-3193
- query-parser-string is vulnerable to Prototype Pollution - CVE-2025-63704
- json-schema-editor-visual vulnerable to prototype pollution - CVE-2025-57320
You might also like:
See something that needs correcting? Let us knowUpdated October 24, 2025


