CVE-2025-49223: Naver Billboard.js

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

Affected products

  • Naver Billboard.js: before 3.15.1 (fixed in 3.15.1)

Published 2025-06-04. Last modified 2026-06-17.