Executive brief
magix-combine-ex is a JavaScript build utility used to combine and process dependencies in frontend projects. A prototype pollution vulnerability allows attackers to inject malicious properties into JavaScript objects, causing denial of service and potentially affecting the integrity of processed code. Applications using this library for their build pipeline may experience disrupted builds or contaminated output.
Technical details
A prototype pollution vulnerability exists in the util-deps.addFileDepend function of magix-combine-ex through version 2.2.2 (CWE-1321). By supplying a crafted payload, an attacker can inject properties on Object.prototype, which affects all objects in the JavaScript runtime. The vulnerability is triggered during dependency processing and requires network access or ability to supply malicious input to the build utility. Exploitation can lead to denial of service; further impact depends on how the polluted objects are used by downstream code. No patch information is currently available in the advisory.
Affected products
- magix-combine-ex contributors magix-combine-ex through 2.2.2
Timeline
- 2025-09-24: disclosed
- 2025-09-25: other: Advisory modified