CVE-2025-65587

No Score

Description

Version 1.6.1 of the Flash Payments package graphql-upload-minimal is vulnerable to prototype pollution. This vulnerability, located in the processRequest() function, allows an attacker to inject special property names into the operations.variables object and pollute global object prototypes, ultimately impacting the entire Node.js process.

References

https://kb.cert.org/vuls/id/907705

Details

Source: Mitre, NVD

Published: 2026-03-14