Description
Note that this vulnerability is only present when using
experimental_caller/experimental_nextAppDirCaller.
Recommendation
Update the @trpc/server package to the latest compatible version. Followings are version details:
Affected version(s): **>= 11.0.0, < 11.8.0 >= 10.27.0, < 10.45.3** Patched version(s): **11.8.0 10.45.3**
References
Could your website be exposed too?
SmartScanner can check your website for tRPC has possible prototype pollution in `experimental_nextAppDirCaller` and gives you actionable findings to investigate.
Start a free scanRelated Issues
- `sveltekit-superforms` has Prototype Pollution in `parseFormData` function of `formData.js` - CVE-2025-62381
- Vuetify has a Prototype Pollution vulnerability - CVE-2025-8083
- messageformat has a prototype pollution vulnerability - CVE-2025-57349
- Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions - lodash-amd - CVE-2025-13465
You might also like:
See something that needs correcting? Let us knowUpdated December 16, 2025


