content-security-policy-parser parses content security policy directives. A prototype pollution vulnerability exists in versions 0.5.0 and earlier, wherein if a policy name is called __proto__, one can override the Object prototype. This issue has been patched in version 0.6.0. A workaround involves disabling prototype method in NodeJS, neutralizing all possible prototype pollution attacks. Provide either --disable-proto=delete (recommended) or --disable-proto=throw as an argument to node to enable this feature.
History

Tue, 12 Aug 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Content-security-policy-parser Project
Content-security-policy-parser Project content-security-policy-parser
Vendors & Products Content-security-policy-parser Project
Content-security-policy-parser Project content-security-policy-parser

Tue, 12 Aug 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Description content-security-policy-parser parses content security policy directives. A prototype pollution vulnerability exists in versions 0.5.0 and earlier, wherein if a policy name is called __proto__, one can override the Object prototype. This issue has been patched in version 0.6.0. A workaround involves disabling prototype method in NodeJS, neutralizing all possible prototype pollution attacks. Provide either --disable-proto=delete (recommended) or --disable-proto=throw as an argument to node to enable this feature.
Title content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE
Weaknesses CWE-1321
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-12T16:02:44.952Z

Updated: 2025-08-12T17:53:03.769Z

Reserved: 2025-08-07T18:27:23.307Z

Link: CVE-2025-55164

cve-icon Vulnrichment

Updated: 2025-08-12T17:52:53.732Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-12T16:15:29.253

Modified: 2025-08-13T17:34:12.350

Link: CVE-2025-55164

cve-icon Redhat

No data.