CVE-2025-13158 | Sonatype Security Advisory

CVE-2025-13158

Summary

Prototype pollution vulnerability in apidoc-core versions 0.2.0 and all subsequent versions allows remote attackers to modify JavaScript object prototypes via malformed data structures, including the “define” property processed by the application, potentially leading to denial of service or unintended behavior in applications relying on the integrity of prototype chains. This affects the preProcess() function in api_group.js, api_param_title.js, api_use.js, and api_permission.js worker modules.

Severity rating

Severity: Critical - 9.3

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Weakness enumeration

CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Credits

James Montaño of the Sonatype Security Research Team

Latest CVE Disclosures

[CVE-2025-12183

org.lz4:lz4-java - Out-of-Bounds Memory Access](/content/security-advisories/cve-2025-12183/index.html) [CVE-2025-1945

Pickescan - Bypass Malicious Pickle Detection inside PyTorch Models via ZIP File Flag Bits](/content/security-advisories/cve-2025-1945/index.html) [CVE-2025-1944

Picklescan - Security Scanning Bypass via Non-Standard File Extensions](/content/security-advisories/cve-2025-1944/index.html) [CVE-2025-1889

Picklescan - Security Scanning Bypass via Non-Standard File Extensions](/content/security-advisories/cve-2025-1889/index.html) [CVE-2025-1716

Picklescan - Security Scanning Bypass Via 'Pip Main'](/content/security-advisories/cve-2025-1716/index.html)