Junglewise Threat Intelligence

CVE-2025-57319: fast-redact prototype pollution in nestedRestore

CVE-2025-57319 · Severity: medium · CVSS 4 · Published 2025-09-24

Vendors: npm.

Executive brief

fast-redact is a JavaScript library used for rapid object redaction/masking in Node.js applications. A prototype pollution vulnerability in its nestedRestore function allows attackers to inject properties into Object.prototype through crafted payloads, potentially causing denial of service or unexpected behavior across an application's object model.

Technical details

The vulnerability is a prototype pollution flaw (CWE-1321) in the nestedRestore function of fast-redact versions 3.5.0 and earlier. An attacker can supply a specially crafted payload to inject properties on Object.prototype, which affects all JavaScript objects in the runtime. The attack requires network access (if the library processes untrusted input) but no authentication. The primary documented impact is denial of service; however, prototype pollution can have cascading effects depending on how the application uses object properties. The advisory was withdrawn because the vulnerable function is undocumented and internal, though the issue references exist and a fix was being pursued.

Affected products

  • fast-redact fast-redact 3.5.0 and earlier

Timeline

  • 2025-09-24: disclosed: Advisory published
  • 2025-09-29: other: GitHub reviewed vulnerability
  • 2025-11-20: other: Advisory withdrawn due to use of undocumented internal function

References