CVE-2025-57349
Published Sep 24, 2025The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message…
Vendor/product archive
1 CVEs tagged to openjsf / messageformat — 0 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message…