CVE-2023-46308: Plotly Plotly.js

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.

Affected products

  • Plotly Plotly.js: before 2.25.2 (fixed in 2.25.2)

Published 2024-01-03. Last modified 2026-06-17.