Executive brief
Rollbar is an error tracking and debugging service for JavaScript applications. A prototype pollution vulnerability in the utility.set function allows attackers to inject malicious properties into JavaScript objects, potentially causing application crashes or unexpected behavior that could disrupt service availability.
Technical details
A prototype pollution vulnerability exists in the utility.set function of Rollbar v2.26.4 and earlier. The vulnerability allows attackers to inject properties on Object.prototype by supplying a crafted payload. The attack requires network access and no authentication or user interaction. Exploitation can lead to denial of service (DoS) and potentially other impacts. This advisory has been withdrawn as a duplicate of GHSA-r8c2-2qwq-94p6; patches or mitigations should be tracked under the primary advisory.
Affected products
- Rollbar rollbar v2.26.4 and earlier
Timeline
- 2025-09-24: disclosed: CVE-2025-57325 published
- 2025-10-20: other: Advisory withdrawn as duplicate of GHSA-r8c2-2qwq-94p6