billboard.js Prototype Pollution Vulnerability Allowing Arbitrary Code Execution or Denial-of-Service

Vulnerability

A prototype pollution vulnerability has been identified in billboard.js versions prior to 3.15.1. The issue arises in the 'generate' function, where attackers can inject arbitrary properties, potentially leading to the execution of arbitrary code or causing a denial-of-service condition.

Impact

Exploitation of this vulnerability could result in prototype pollution, allowing for the injection of arbitrary properties. This could be leveraged to execute arbitrary code or cause a denial-of-service condition.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.