Intel

AIKIDO-2025-10265

billboard.js is vulnerable to Prototype Pollution

Prototype PollutionCVE-2025-49223 Published Apr 23, 2025

71

High Risk

This Affects:

JSbillboard.js
1.9.0 - 3.15.0
Fixed in 3.15.1
Are you affected? Scan for Free

TL;DR

Several security vulnerabilities were quietly patched in billboard.js version 3.15.1. A prototype pollution flaw impacted the generate and mergeObj the function, posing a significant risk.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

billboard.js is vulnerable to Prototype Pollution in versions 1.9.0 - 3.15.0.

How to fix this

Upgrade the billboard.js library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform