CVE advisoryCRITICAL
CVE-2025-13158
apidoc-core Prototype Pollution Affecting JavaScript Object Prototypes
Halo Surface Signal: 3 out of 5 — possibly public-facing.
A prototype pollution vulnerability in apidoc-core allows remote attackers to modify JavaScript object prototypes via malformed data structures, potentially leading to denial of service or unintended application behavior. This could impact applications processing external data if the affected functions are reachable.