Web3js is a JavaScript library for interacting with Ethereum and other blockchain networks, with a modestly represented vulnerability footprint concentrated in its core method and subscription components. The durable signal centers on prototype-pollution weaknesses, a class of client-side injection flaw that can arise in JavaScript codebases handling untrusted input or dynamic object manipulation. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Web3js over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-57330HIGH The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in the attachToObject function of web3-core-subscriptions versi | Sep 24, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-57329HIGH web3-core-method is a package designed to creates the methods on the web3 modules. A Prototype Pollution vulnerability in the attachToObject function of web3-core-method version 1. | Sep 24, 2025 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Web3js.
Media articles that mention a CVE ID that affects a product developed by Web3js — matched by CVE ID, not by vendor name.