Executive brief
billboard.js is a popular JavaScript charting library used to render data visualizations in web applications. A prototype pollution vulnerability in its generate function allows attackers to inject malicious properties into JavaScript objects, enabling arbitrary code execution or denial-of-service attacks. This could compromise any web application using affected versions of the library.
Technical details
The vulnerability is a prototype pollution flaw (CWE-1321) in the generate function of billboard.js versions before 3.15.1. Prototype pollution allows an attacker to modify the prototype of JavaScript objects by injecting arbitrary properties, which affects all objects inheriting from that prototype. The attack requires only network access with no authentication or user interaction, as malicious input can be crafted and sent to an application using the library. An attacker can leverage this to execute arbitrary code or trigger denial of service conditions. The fix is available in version 3.15.1 and later.
Affected products
- Naver billboard.js before 3.15.1
Timeline
- 2025-06-04: disclosed: Vulnerability published in OSV
- 2025-06-04: patched: Fix available in version 3.15.1