Vulnerabilities (CVE)

Filtered by vendor Keyangxiang
Filtered by product Csvtojson
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-57350 1 Keyangxiang 1 Csvtojson 2025-10-17 N/A 8.6 HIGH
The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototype pollution vulnerability in versions prior to 2.0.10. This issue arises due to insufficient sanitization of nested header names during the parsing process in the parser_jsonarray component. When processing CSV input containing specially crafted header fields that reference prototype chains (e.g., using __proto__ syntax), the application may unintentionally modify properties o ...

Show More