Impact
The flaw resides in the ObjectUtils.mutateFieldData function of primefaces primereact. A crafted Field argument can cause improper modification of JavaScript object prototype attributes, leading to prototype pollution. The CVE notes that this attack is possible remotely, but no confirmed exploitation is documented. The weakness maps to CWE-1321, CWE-915, and CWE-94.
Affected Systems
This weakness affects primefaces primereact versions up to and including 10.9.8. Any deployment that uses a release within that range and that is no longer supported by the maintainer is potentially exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The attack vector is remote, but no active exploit has been publicly described.
OpenCVE Enrichment