Executive brief
Antv Layout is a software library used for graph visualization and layout calculations. A security flaw in the library's object handling utility allows an attacker to modify the fundamental behavior of the application by injecting malicious data. This could lead to application crashes, unauthorized data access, or the bypassing of security logic, depending on how the library is integrated into a specific service.
Technical details
A prototype pollution vulnerability exists in the `setNestedValue` function within `lib/util/object.js` of antv layout 2.0.0. The function accepts a dot-separated path and writes values to a target object without filtering dangerous keys such as `__proto__` or `constructor.prototype`. A remote attacker with the ability to provide input to this function can pollute the global `Object.prototype`. This can lead to various impacts including denial of service or logic bypasses. As of the advisory date, the project maintainers have been notified but a formal patch has not been released.
Affected products
- antv layout 2.0.0
Timeline
- 2026-06-11: disclosed: Issue reported to the project via GitHub
- 2026-07-13: advisory: CVE published by NVD/VulDB