Generated remediation guidance and an executive summary. No account required.
The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing untrusted user input to util.setProperty or to ReflectionObject.setParsedOption functions 2. by parsing/loading .proto files
Cite this page
CVE-2022-25878. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2022-25878
Use CWE-1321, Protobufjs Project vendor hub and Protobufjs product page to widen CVE-2022-25878 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-36665, CVE-2026-41242 and CVE-2018-3738 for nearby disclosures in the same product family.