Security Advisory

CVE-2025-8101

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-25 21:52:47
Last updated 2025-12-03 21:04:19
Assigner Fluid Attacks
CVSS score 8.8
State PUBLISHED

Description

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Linkify (linkifyjs) allows XSS Targeting HTML Attributes and Manipulating User-Controlled Variables.This issue affects Linkify: from 4.3.1 before 4.3.2.