Junglewise Threat Intelligence

CVE-2025-57354: martinandert counterpart prototype pollution in translate method

CVE-2025-57354 · Severity: low · CVSS 3.1 · Published 2025-09-24

Vendors: npm.

Executive brief

Counterpart is a translation and localization library used in Node.js and web applications to manage multi-language support. A security flaw allows attackers to inject malicious data into the application's core JavaScript environment by providing specially crafted translation keys. This could lead to application crashes (denial of service) or, in some cases, allow an attacker to execute unauthorized code on the server or in a user's browser.

Technical details

A prototype pollution vulnerability (CWE-1321) exists in the 'counterpart' library due to insufficient sanitization of user-controlled input during translation key processing. Attackers can supply maliciously crafted keys containing prototype chain elements (e.g., '__proto__') to the 'translate' method. When combined with specific separator configurations, this allows the injection of arbitrary properties into the global JavaScript Object prototype. This can be exploited to cause a denial-of-service or achieve remote code execution depending on the application's environment. The issue is addressed in version 0.18.6.

Affected products

  • martinandert counterpart < 0.18.6

Timeline

  • 2025-08-06: other: Issue reported to maintainer
  • 2025-09-24: disclosed: CVE-2025-57354 published
  • 2025-09-24: advisory: GHSA-2488-w585-72ch published

References