Junglewise Threat Intelligence

CVE-2025-57320: json-schema-editor-visual prototype pollution in setData and deleteData

CVE-2025-57320 · Severity: low · CVSS 3.1 · Published 2025-09-24

Vendors: npm.

Executive brief

A security vulnerability has been identified in json-schema-editor-visual, a tool used by developers to create and edit JSON schemas. An attacker can exploit this flaw to crash the application or cause it to behave unpredictably by sending specially crafted data. This could lead to a denial-of-service, making the editor or the application using it unavailable to users.

Technical details

A prototype pollution vulnerability (CWE-1321) exists in the setData and deleteData functions of json-schema-editor-visual through version 1.1.1. The vulnerability arises from insufficient sanitization of user-supplied property paths, allowing an attacker to inject or delete properties on the global Object.prototype using nested keys like '__proto__'. This can be exploited remotely without authentication by providing a malicious payload during standard schema processing. Successful exploitation can lead to application instability or a denial-of-service (DoS) condition. While some sources suggest versions up to 2.0.0 may be affected, official records indicate the flaw is present in versions up to and including 1.1.1.

Affected products

  • open-federation json-schema-editor-visual <= 1.1.1

Timeline

  • 2025-09-24: disclosed
  • 2025-09-24: advisory

References