Prototype pollution in fast-redact - CVE-2025-57319
Published: November 7, 2025 / Updated: November 8, 2025
Vulnerability identifier: #VU118206
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-57319
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to improper input validation. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.
Affected software
fast-redact
Astronomer with IBM
watsonx Orchestrate Developer Edition
WatsonX BI Assistant
IBM Event Endpoint Management
IBM Observability with Instana
Event Streams
Astronomer with IBM
watsonx Orchestrate Developer Edition
WatsonX BI Assistant
IBM Event Endpoint Management
IBM Observability with Instana
Event Streams
How to mitigate CVE-2025-57319
Install update from vendor's website.
Astronomer with IBM - update to 1.1.0
IBM Observability with Instana - update to 1.0.307
watsonx Orchestrate Developer Edition - update to 2.3.0
WatsonX BI Assistant - update to 5.2.2
IBM Event Endpoint Management - update to 11.7.0
Event Streams - update to 12.2.0
IBM Observability with Instana - update to 1.0.307
watsonx Orchestrate Developer Edition - update to 2.3.0
WatsonX BI Assistant - update to 5.2.2
IBM Event Endpoint Management - update to 11.7.0
Event Streams - update to 12.2.0
External References
Related Security Bulletins
- Prototype pollution in fast-redact
- Multiple vulnerabilities in IBM WatsonX BI Assistant for CP4D
- Multiple vulnerabilities in IBM Event Streams
- Astronomer with IBM update for fast-redact
- Multiple vulnerabilities in IBM Event Endpoint Management
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM watsonx Orchestrate Developer Edition