SCA: security update for radashi (GHSA-2xv9-ghh9-xc69)

high Tenable Cloud Security Plugin ID 427748

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Radashi is a TypeScript utility toolkit. Prior to version 12.5.1, the set function within the Radashi
library is vulnerable to prototype pollution. If an attacker can control parts of the path argument to the
set function, they could potentially modify the prototype of all objects in the JavaScript runtime,
leading to unexpected behavior, denial of service, or even remote code execution in some specific
scenarios. This issue has been patched in version 12.5.1. A workaround for this issue involves sanitizing
the path argument provided to the set function to ensure that no part of the path string is __proto__,
prototype, or constructor. (CVE-2025-48054)

See Also

https://github.com/advisories/GHSA-2xv9-ghh9-xc69

Plugin Details

Severity: High

ID: 427748

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 5/27/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.49

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2025-48054

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.8

Threat Score: 6.8

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/27/2025

Vulnerability Publication Date: 5/27/2025

Reference Information

CVE: CVE-2025-48054