Junglewise Threat Intelligence

CVE-2025-57328: jonschlinkert toggle-array prototype pollution in enable and disable functions

CVE-2025-57328 · Severity: medium · CVSS 4 · Published 2025-09-24

Vendors: npm, Jonschlinkert.

Executive brief

The toggle-array library, a utility used to manage properties within arrays of objects, is vulnerable to a security flaw that allows attackers to manipulate the fundamental behavior of the application. By providing specially crafted data, an attacker can inject unauthorized properties into the global object prototype. This can lead to application crashes, service outages, or unpredictable behavior across the entire software environment.

Technical details

A prototype pollution vulnerability (CWE-1321) exists in the 'enable' and 'disable' functions of the toggle-array package through version 1.0.1. The vulnerability arises from improper validation of input when modifying object properties within an array, allowing an attacker to inject or modify properties on 'Object.prototype'. This is achievable via a network-based attack vector without authentication. Successful exploitation can lead to a Denial of Service (DoS) or potentially other side effects depending on how the polluted properties are used by the application. As of the advisory date, users should check for updates or implement input validation to prevent malicious payloads from reaching these functions.

Affected products

  • jonschlinkert toggle-array <= 1.0.1

Timeline

  • 2025-09-24: disclosed
  • 2025-09-24: advisory

References