Junglewise Threat Intelligence

CVE-2025-57353: messageformat prototype pollution in @messageformat/runtime

CVE-2025-57353 · Severity: low · CVSS 3.1 · Published 2025-09-24

Vendors: npm.

Executive brief

messageformat is a Node.js library used to format and parse messages across different languages and locales. A prototype pollution vulnerability in the @messageformat/runtime component (version 3.0.1) allows attackers with access to untrusted message data to inject arbitrary properties into JavaScript's global Object prototype. This can cause denial of service, unexpected application behavior, or create opportunities for further exploitation affecting all objects created in the application.

Technical details

This is a CWE-1321 prototype pollution vulnerability in the @messageformat/runtime package version 3.0.1. The root cause is insufficient validation of nested message keys in the addMessages method during message data processing. An attacker can provide specially crafted input containing keys like __proto__ to manipulate the JavaScript prototype chain and inject arbitrary properties into Object.prototype. The attack requires the application to process untrusted input data through the vulnerable runtime components, with no authentication or special user interaction required. Successful exploitation can result in denial of service through corrupted object prototypes or unexpected application behavior. The vulnerability is fixed in version 3.0.2.

Affected products

  • messageformat @messageformat/runtime 3.0.1

Timeline

  • 2025-09-24: disclosed: Advisory published on OSV and NVD
  • 2025-09-24: patched: Fix released in version 3.0.2

References