Intel

AIKIDO-2025-10167

@syncfusion/ej2-base is vulnerable to Prototype Pollution

Prototype Pollution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 19, 2025

85

High Risk

This Affects:

JS@syncfusion/ej2-base
1.0.8 - 28.2.11
Fixed in 28.2.12
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to prototype pollution due to unsafe handling of object properties in the setValue function. When setting a value for the nameSpace in a target object, an attacker can manipulate the prototype, potentially leading to unexpected behavior, security vulnerabilities, or denial of service.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@syncfusion/ej2-base is vulnerable to Prototype Pollution in versions 1.0.8 - 28.2.11.

How to fix this

Upgrade the @syncfusion/ej2-base library to the patch version.