tRPC has possible prototype pollution in `experimental_nextAppDirCaller`
- Severity:
- High
Description
Note that this vulnerability is only present when using
experimental_caller/experimental_nextAppDirCaller.
Recommendation
Update the @trpc/server package to the latest compatible version. Followings are version details:
Affected version(s): **>= 11.0.0, < 11.8.0 >= 10.27.0, < 10.45.3** Patched version(s): **11.8.0 10.45.3**
References
Related Issues
- x402 SDK vulnerable in outdated versions in resource servers for builders - Vulnerability
- tRPC 11 WebSocket DoS Vulnerability - CVE-2025-43855
- Potential DoS when using ContextLines integration (GHSA-r5w7-f542-q2j4) 9 - Vulnerability
- Potential DoS when using ContextLines integration (GHSA-r5w7-f542-q2j4) 8 - Vulnerability
- Tags:
- npm
- @trpc/server
Anything's wrong? Let us know Last updated on December 16, 2025