Intel

AIKIDO-2025-10255

@pandacss/studio is vulnerable to Prototype Pollution

Prototype Pollution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 22, 2025

43

Medium Risk

This Affects:

js@pandacss/studio
0.30.0 - 0.53.3
Fixed in 0.53.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to prototype pollution in the mergeProps function, which can be exploited to modify object prototypes and potentially lead to a denial of service (DoS) or unexpected application behavior.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

@pandacss/studio is vulnerable to Prototype Pollution in versions 0.30.0 - 0.53.3.

How to fix this

Upgrade the @pandacss/studio library to the patch version.