Executive brief
messageformat is a JavaScript library that implements the Unicode MessageFormat 2 specification for handling multi-language text messages. A prototype pollution vulnerability allows attackers to inject malicious properties into JavaScript's global object prototype through specially crafted message keys, potentially causing application crashes or unexpected behavior in any application using this library to process untrusted message definitions.
Technical details
This is a prototype pollution vulnerability (CWE-1321) in the messageformat library versions prior to 2.3.0. The root cause is improper sanitization of nested message key paths containing special characters (e.g., __proto__), which allows attackers to modify the JavaScript Object prototype chain. An attacker can exploit this by providing specially crafted message definitions with malicious key paths; no authentication or user interaction is required if the application processes untrusted message input. Successful exploitation can lead to denial of service, undefined application behavior, or property injection into the global object. The vulnerability was patched in version 2.3.0 and 3.0.0-beta.0.
Affected products
- messageformat messageformat < 2.3.0
Timeline
- 2025-09-24: disclosed: CVE-2025-57349 published
- 2025-09-25: patched: Advisory reviewed; patch available in version 2.3.0 and 3.0.0-beta.0