Intel

AIKIDO-2025-10314

dt_for_itables is vulnerable to Prototype Pollution

Prototype Pollution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 19, 2025

61

Medium Risk

This Affects:

JSdt_for_itables
2.0.10 - 2.3.0
Fixed in 2.3.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to prototype pollution due to the indirect evaluation of JavascriptCode and JavascriptFunction. It could enable modifications to object prototypes, which, depending on how the application handles the polluted objects, may lead to issues such as denial of service, privilege escalation, or remote code execution. An attacker can exploit a vulnerability by manipulating input to bypass the checks of the indirect evaluation of JavaScript code. By crafting malicious input that evades this check, the attacker can inject arbitrary properties into the prototype chain, resulting in what is known as prototype pollution.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

dt_for_itables is vulnerable to Prototype Pollution in versions 2.0.10 - 2.3.0.

How to fix this

Upgrade the dt_for_itables library to a patch version.