{"id":"GHSA-xcg2-9pp4-j82x","summary":"rollbar vulnerable to Prototype Pollution in merge()","details":"### Impact\n\nPrototype pollution vulnerability in merge(). If application code calls `rollbar.configure()` with untrusted input, prototype pollution is possible.\n\n### Patches\n\nFixed in 2.26.5 and 3.0.0-beta5.\n\n### Workarounds\n\nEnsure that values passed to `rollbar.configure()` do not contain untrusted input.\n\n### References\n\nFixed in https://github.com/rollbar/rollbar.js/pull/1394 (2.26.x) and https://github.com/rollbar/rollbar.js/pull/1390 (3.x)","aliases":["CVE-2025-62517"],"modified":"2025-10-24T19:28:46Z","published":"2025-10-23T20:31:30Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-10-23T20:31:30Z","nvd_published_at":"2025-10-23T20:15:41Z","cwe_ids":["CWE-1321"]},"references":[{"type":"WEB","url":"https://github.com/rollbar/rollbar.js/security/advisories/GHSA-xcg2-9pp4-j82x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62517"},{"type":"WEB","url":"https://github.com/rollbar/rollbar.js/pull/1390"},{"type":"WEB","url":"https://github.com/rollbar/rollbar.js/pull/1394"},{"type":"WEB","url":"https://github.com/rollbar/rollbar.js/commit/61032fe6c208b71e249514800808a54bcb8cb8bb"},{"type":"WEB","url":"https://github.com/rollbar/rollbar.js/commit/d717def8b68f4a947975d0aebb729869cdb2d343"},{"type":"PACKAGE","url":"https://github.com/rollbar/rollbar.js"}],"affected":[{"package":{"name":"rollbar","ecosystem":"npm","purl":"pkg:npm/rollbar"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.26.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-xcg2-9pp4-j82x/GHSA-xcg2-9pp4-j82x.json","last_known_affected_version_range":"\u003c= 2.26.4"}},{"package":{"name":"rollbar","ecosystem":"npm","purl":"pkg:npm/rollbar"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0-alpha1"},{"fixed":"3.0.0-beta5"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.0.0-beta4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-xcg2-9pp4-j82x/GHSA-xcg2-9pp4-j82x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}