-
Notifications
You must be signed in to change notification settings - Fork 953
Open
Description
What happened?
While working on opentelemetry-js project, I discovered a security vulnerability (CVE-2025-64718) in the js-yaml package. Versions 4.1.0 and below are affected by a prototype pollution issue that allows attackers to modify the object prototype through crafted YAML input. This can lead to unexpected or unsafe application behavior.
OpenTelemetry Setup Code
package.json
Relevant log output
Operating System and Version
No response
Runtime and Version
No response
Tip
React with 👍 to help prioritize this issue. Please use comments to provide useful context, avoiding +1 or me too, to help us triage it. Learn more here.
Metadata
Metadata
Assignees
Labels
No labels