CVE-2025-32014: Remcohaszing Estree-Util-Value-To-Estree
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed in 3.3.3.
Affected products
- Remcohaszing Estree-Util-Value-To-Estree: before 3.3.3 (fixed in 3.3.3)
Published 2025-04-07. Last modified 2026-06-17.