Intel

AIKIDO-2025-10221

chartist is vulnerable to Prototype Pollution

Prototype PollutionCVE-2024-45435

98

Critical Risk

This Affects:

JSchartist
1.0.0 - 1.3.0
Fixed in 1.3.1

TL;DR

Affected versions of the chartist package are vulnerable to prototype pollution due to missing validation when assigning object properties. An attacker can exploit this by injecting malicious properties via the __proto__ key, which can recursively pollute the object prototype and affect all objects across the application.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

chartist is vulnerable to Prototype Pollution in versions 1.0.0 - 1.3.0.

How to fix this

Upgrade the chartist library to the patch version.

Background Info