CVE-2025-32014

estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed in 3.3.3.

Open
LOW (0.7)
  • logo

    System detected CVE-2025-32014

  • logo

    System

  • logo

    System

  • logo

    System

  • logo

    System

  • logo

    System updated the risk assessment from 0 to 0.67

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment from 0.67 to 1.35

    System recalculated raw risk assessment

  • logo

    System fixed CVE-2025-32014

  • logo

    System detected CVE-2025-32014 with a risk of 0.67

Add a comment

Mark as False Positive
Last calculated at:

Affected component

estree-util-value-to-estree

Installed version:
1.3.0
Fixed in:
3.3.3

Quick Fix

Update all Dependencies
Update only estree-util-value-to-estree

Management decisions across the organization

Copyright © 2025 L3montree GmbH and the DevGuard Contributors. All rights reserved. Version 2ab7b793efd72421aea8c3a994ac60202bf1b3a5