External risk intelligence

apidoc-core Prototype Pollution Affecting JavaScript Object Prototypes

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-13158

The vulnerability exists in a documentation generation library (apidoc-core). While such tools are often used in build-time or internal development environments, they may be integrated into automated workflows or public-facing documentation portals that process external data, making internet reachability possible depending on the specific deployment context.

Denial of Service

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A prototype pollution vulnerability in apidoc-core affects how JavaScript object prototypes are handled, potentially leading to denial of service or unexpected application behavior if malformed data is processed.

  • Issue: Malicious data can alter core object behavior.
  • Leadership Concern: Understand potential impacts on dependent systems.
  • Takeaway: Confirm if this documentation tool is in use.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted data, potentially over the internet, to an application that uses the apidoc-core library. The malformed data, which includes a "define" property, targets the library's data processing functions. Successful exploitation can lead to modification of JavaScript object prototypes, resulting in denial of service or unexpected application behavior.

  • No authentication or special access needed.
  • Malformed data sent to processing functions.
  • Potential for denial of service or unexpected behavior.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in apidoc-core could affect applications that process malformed data structures using the “define” property. When supported by the advisory, this could lead to denial of service or unexpected behavior due to modifications in JavaScript object prototypes.

  • Application logic and behavior.
  • Via malformed input data.
  • Unintended application behavior.

Operational Fix

Recommended remediation, mitigation, and detection steps

This prototype pollution vulnerability in apidoc-core affects applications processing malformed data structures. Security and platform teams should initiate by identifying all instances of apidoc-core, assessing their exposure and criticality, and then coordinating remediation with application owners.

  • Ownership: Application and platform teams.
  • Verify first: Identify and assess exposure.
  • Action: Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is apidoc-core and how is it used?

apidoc-core is a library for generating documentation from source code comments in JavaScript applications. Developers use it to automatically build API reference websites or manuals. It functions as a utility within the development lifecycle or build pipeline, parsing data structures to produce human-readable documentation based on how developers define their APIs.

What does prototype pollution mean in CVE-2025-13158?

This vulnerability is a type of Improper Neutralization of Special Elements used in an OS Command or argument, specifically categorized as CWE-1321. In simple terms, an attacker sends specially crafted data that tricks the software into modifying the foundational 'blueprint'—or prototype—that all JavaScript objects share. By polluting this shared foundation, the attacker can force the application to behave in unintended ways or cause it to crash.

How do attackers trigger this vulnerability?

An attacker triggers the bug by submitting malformed data containing a specific 'define' property to the application. This input is processed by vulnerable worker modules like api_group.js. Crucially, the vulnerability relies on the library processing this malicious data structure; if the application does not pass external or untrusted data into these specific documentation processing functions, the prototype remains safe from this specific input.

Is my application at risk for CVE-2025-13158?

Risk depends on how you use the library. According to Halo Surface Signal, while apidoc-core is often used in internal build environments, it becomes a greater concern if your specific deployment integrates this tool into automated workflows or public-facing portals that process external, user-supplied data. If the library processes data originating from the internet, the potential for unauthorized interaction increases.

How should I start responding to this threat?

Your first step is to perform an inventory of your environment to identify where apidoc-core is installed or utilized. Once identified, work with your application owners to determine if these instances handle data from untrusted sources or the open internet. After assessing this exposure and the criticality of the specific service, coordinate with your development teams to plan a risk-based remediation.

References