Impact
A weakness has been identified in antv layout 2.0.0. The vulnerability is limited to the function setNestedValue in lib/util/object.js, where a crafted path argument can cause the function to modify JavaScript prototype attributes. This leads to prototype pollution, allowing an attacker to alter the behavior of objects globally across the application. The flaw can be triggered remotely by providing a malicious path argument through an external input surface.
Affected Systems
The issue affects the antv layout JavaScript library, version 2.0.0. No other versions or vendor products are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low but non‑zero exploitation probability. The vulnerability is not listed in CISA KEV, and no publicly available exploit or proof‑of‑concept has been reported at this time, indicating a limited likelihood of exploitation.
OpenCVE Enrichment