#VU124030 Prototype pollution in node-csvtojson - CVE-2025-57350
Published: March 16, 2026
node-csvtojson
Keyang
Description
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to insufficient sanitization of nested header names during the parsing process in the parser_jsonarray component. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.