Skip to main content

Vendor/product archive

openjsf / messageformat CVEs

Beta · best-effort

1 CVEs tagged to openjsf / messageformat0 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2025-57349

Published Sep 24, 2025

The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1