CVE-2025-8083 describes a Prototype Pollution vulnerability in Vuetify versions 2.2.0-beta.2 through 3.0.0-alpha.9, stemming from the 'mergeDeep' utility function used in its Preset configuration feature. This flaw allows attackers to inject arbitrary properties into all JavaScript objects, potentially leading to resource exhaustion, denial of service, or unauthorized data access, and can impact server processes if Server-Side Rendering (SSR) is used. Rated 8.6 HIGH on CVSS, the vulnerability has a network attack vector and low attack complexity, but there is currently no evidence of active exploitation, public exploit code, or significant community discussion. Vuetify v2 is End-of-Life and will not receive a patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Vuetify | >=2.2.0-beta.2 <3.0.0-alpha.10CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.