Junglewise Threat Intelligence

CVE-2025-8101: Linkify prototype pollution and XSS in assign helper

CVE-2025-8101 · Severity: high · CVSS 4 · Published 2025-07-26

Vendors: npm.

Executive brief

Linkify is a software library used to automatically find and convert text links into clickable HTML links. A security flaw in the library allows attackers to inject malicious code into web pages that use it. This could lead to unauthorized actions being performed in a user's browser, such as stealing session information or redirecting users to malicious websites.

Technical details

A prototype pollution vulnerability exists in the internal `assign()` helper function of Linkify version 4.3.1. The root cause is the lack of proper filtering for the `__proto__` property, allowing an attacker to modify the base object prototype. By polluting the prototype, an attacker can perform HTML attribute injection, specifically injecting malicious event handlers. This results in either Stored or Reflected Cross-Site Scripting (XSS), enabling arbitrary JavaScript execution in the context of the victim's browser. The issue is resolved in version 4.3.2.

Affected products

  • Linkify linkifyjs 4.3.1

Timeline

  • 2025-07-25: disclosed: NVD publication date
  • 2025-07-26: advisory: GitHub Advisory published
  • 2025-07-26: patched: Version 4.3.2 released

References