Prototype pollution in node-csvtojson - CVE-2025-57350
Published: March 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to insufficient sanitization of nested header names during the parsing process in the parser_jsonarray component. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.
Affected software
IBM Cloud Pak for Security
QRadar Suite
How to mitigate CVE-2025-57350
IBM Cloud Pak for Security - update to 1.11.9.0
QRadar Suite - update to 1.11.9.0