Intel

AIKIDO-2025-10081

php-date-formatter is vulnerable to Prototype Pollution

Prototype PollutionCVE-2024-57063

40

Medium Risk

This Affects:

JSphp-date-formatter
1.2.0 - 1.3.6
Fixed in 1.3.7

TL;DR

Affected versions of php-date-formatter are vulnerable to a prototype pollution when using the DateFormatter class.

Who does this affect?

You are affected if you use a vulnerable version of php-date-formatter.

Background info

php-date-formatter is vulnerable to Prototype Pollution in versions 1.2.0 - 1.3.6.

How to fix this

Upgrade php-date-formatter to a patch version.

Background Info