CVE-2023-46308

9.8CRITICAL

In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.

Published: 1/3/2024Updated: 12/24/2025

Description

In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.

AI AnalysisPowered by AI

Affected Products

plotlyplotly.js

References