Junglewise Threat Intelligence

CVE-2025-57329: web3.js web3-core-method prototype pollution in attachToObject

CVE-2025-57329 · Severity: medium · CVSS 4 · Published 2025-09-24

Vendors: npm.

Executive brief

web3-core-method is a component of the web3.js library used by developers to interact with the Ethereum blockchain. A security flaw allows attackers to manipulate the internal structure of the application's data objects. This can lead to application crashes, service instability, or unpredictable behavior in decentralized applications (dApps) that rely on this library.

Technical details

A prototype pollution vulnerability exists in the attachToObject function of web3-core-method (version 1.10.4 and earlier). The flaw stems from improper handling of constructor arguments during the method initialization process, failing to sanitize user-provided keys such as __proto__. An attacker can exploit this by supplying a crafted payload to inject properties into the global Object.prototype. This can result in a Denial of Service (DoS) or potentially arbitrary code execution depending on the application environment. As the 1.x branch of web3.js is archived and at end-of-life, users are encouraged to migrate to version 4.x.

Affected products

  • web3.js web3-core-method <= 1.10.4

Timeline

  • 2025-09-24: disclosed
  • 2025-09-24: advisory

References