Junglewise Threat Intelligence

CVE-2025-57323: mpregular prototype pollution in event handler

CVE-2025-57323 · Severity: low · CVSS 3.1 · Published 2025-09-24

Vendors: npm.

Executive brief

mpregular is a lightweight JavaScript framework for building web applications. A flaw in its event handler function allows attackers to inject malicious properties into core JavaScript objects, which can degrade performance, break application functionality, or cause complete service outages.

Technical details

A prototype pollution vulnerability exists in the mp.addEventHandler function of mpregular version 0.2.0 and earlier. The vulnerability occurs because user-supplied input is not properly validated before being assigned to Object.prototype properties. An attacker can supply a crafted payload to inject arbitrary properties into the prototype chain, affecting all objects in the application. The attack requires only network access and no authentication; successful exploitation results in denial of service through application malfunction or resource exhaustion. A fix is available in versions after 0.2.0.

Affected products

  • mpregular mpregular 0.2.0 and earlier

Timeline

  • 2025-09-24: disclosed
  • 2025-09-24: advisory: GHSA-xx4g-r65p-3qf2 published

References