AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-13158

UNKNOWN · CVSS N/A EPSS 0.46%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-12-26 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. It affects Java. It may be remotely exploitable. It may lead to a denial-of-service condition.

CVE
CVE-2025-13158
Severity
UNKNOWN
CVSS
N/A
EPSS
0.46%
Java

Original NVD Description

Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to modify JavaScript object prototypes via malformed data structures, including the “define” property processed by the application, potentially leading to denial of service or unintended behavior in applications relying on the integrity of prototype chains. This affects the preProcess() function in api_group.js, api_param_title.js, api_use.js, and api_permission.js worker modules.