Rollbar.js offers error tracking and logging from Javascript to Rollbar. In versions before 2.26.5 and from 3.0.0-alpha1 to before 3.0.0-beta5, there is a prototype pollution vulnerability in merge(). If application code calls rollbar.configure() with untrusted input, prototype pollution is possible. This issue has been fixed in versions 2.26.5 and 3.0.0-beta5. A workaround involves ensuring that values passed to rollbar.configure() do not contain untrusted input.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xcg2-9pp4-j82x rollbar vulnerable to Prototype Pollution in merge()
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 23 Oct 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 20:00:00 +0000

Type Values Removed Values Added
Description Rollbar.js offers error tracking and logging from Javascript to Rollbar. In versions before 2.26.5 and from 3.0.0-alpha1 to before 3.0.0-beta5, there is a prototype pollution vulnerability in merge(). If application code calls rollbar.configure() with untrusted input, prototype pollution is possible. This issue has been fixed in versions 2.26.5 and 3.0.0-beta5. A workaround involves ensuring that values passed to rollbar.configure() do not contain untrusted input.
Title Rollbar.js Prototype Pollution Vulnerability in merge()
Weaknesses CWE-1321
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-10-23T20:16:08.104Z

Reserved: 2025-10-15T15:03:28.134Z

Link: CVE-2025-62517

cve-icon Vulnrichment

Updated: 2025-10-23T20:13:59.361Z

cve-icon NVD

Status : Received

Published: 2025-10-23T20:15:41.057

Modified: 2025-10-23T20:15:41.057

Link: CVE-2025-62517

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.