Executive brief
SassDoc Extras is a utility library used by developers to build themes for SassDoc, a documentation tool for Sass code. A security flaw in this library allows an attacker to manipulate the underlying behavior of the application by injecting malicious data. This can lead to application crashes or unexpected behavior, potentially disrupting the documentation generation process.
Technical details
A prototype pollution vulnerability (CWE-1321) exists in the `byGroupAndType` function of sassdoc-extras versions up to and including 2.5.1. The root cause is the improper validation of user-supplied input when processing structured data, allowing an attacker to inject properties into `Object.prototype`. This is a network-reachable vulnerability that requires no authentication or user interaction. Successful exploitation allows an attacker to manipulate the JavaScript prototype chain, which can result in a Denial of Service (DoS) or potentially arbitrary code execution depending on the environment. As of the advisory date, the vulnerability remains unpatched in the affected versions.
Affected products
- SassDoc sassdoc-extras <= 2.5.1
Timeline
- 2025-09-24: disclosed: Initial disclosure and CVE assignment
- 2025-09-24: advisory: GitHub Advisory published