
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68130 is a prototype pollution vulnerability in the @trpc/server npm package, specifically within the formDataToObject function used by the Next.js App Router adapter. It affects @trpc/server versions >=10.27.0 and <10.45.3, and >=11.0.0 and <11.8.0, and is only exploitable when using the experimental_caller or experimental_nextAppDirCaller features. The vulnerability was published on December 15–16, 2025, with fixes released in versions 10.45.3 and 11.8.0. It carries a CVSS v4 base score of 8.5 (High) (GitHub Advisory, tRPC Security Advisory).
The root cause is classified as CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes — Prototype Pollution). The vulnerable set() function in formDataToObject.ts recursively processes FormData field names using bracket/dot notation (e.g., user[name]) to build nested objects, but performs no validation or sanitization of dangerous keys such as __proto__, constructor, or prototype. When the Next.js App Router adapter receives a FormData input and calls formDataToObject(), an attacker with low-level access can submit field names like __proto__[isAdmin] to directly modify Object.prototype, affecting all subsequently created objects in the Node.js process. A public proof-of-concept demonstrating the attack is included in the official advisory (tRPC Security Advisory, GitHub Advisory).
Successful exploitation can lead to authorization bypass, denial of service, and data integrity compromise. Because Object.prototype is shared across the entire JavaScript runtime, polluting it with attacker-controlled properties (e.g., isAdmin: "true") causes all objects in the application to inherit those properties, potentially granting unauthorized administrative access. Additionally, overwriting built-in prototype methods such as toString with non-function values can crash the application, causing denial of service. The vulnerability affects both the vulnerable system and subsequent systems, with high integrity impact in both scopes (tRPC Security Advisory, GitHub Advisory).
A public proof-of-concept exploit is available in the official GitHub Security Advisory, demonstrating the attack against @trpc/server@11.7.2. As of the time of disclosure, there is no evidence of active in-the-wild exploitation, and no threat actor attribution has been reported. The EPSS score is approximately 0.19% (41st percentile), indicating a relatively low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).
@trpc/server versions >=10.27.0 and <10.45.3 or >=11.0.0 and <11.8.0 with experimental_caller or experimental_nextAppDirCaller enabled and normalizeFormData active.Object.prototype:const formData = new FormData();
formData.append("__proto__[isAdmin]", "true");
formData.append("__proto__[role]", "superadmin");
formData.append("username", "attacker");nextAppDirCaller adapter detects input instanceof FormData and calls formDataToObject(input), which splits __proto__[isAdmin] into ["__proto__", "isAdmin"] and recursively sets Object.prototype.isAdmin = "true".user.isAdmin or similar properties will now return "true" for all objects, granting the attacker elevated privileges.__proto__[toString] with a non-function value to crash the application on any subsequent .toString() call (tRPC Security Advisory, GitHub Advisory).__proto__, constructor, or prototype patterns (e.g., __proto__[isAdmin], constructor[prototype][role]).isAdmin: true on objects that should not have this property); Node.js error logs referencing TypeError on built-in methods like toString or hasOwnProperty if DoS payload was used.TypeError exceptions in the Node.js process following form submissions.Upgrade @trpc/server to version 10.45.3 (for the v10 branch) or 11.8.0 (for the v11 branch), which fix the issue by adding validation of dangerous prototype keys in formDataToObject (GitHub Advisory). If an immediate upgrade is not possible, disable experimental_caller / experimental_nextAppDirCaller in your tRPC configuration to eliminate the vulnerable code path. Additionally, implement server-side input validation to reject FormData field names containing __proto__, constructor, or prototype as a defense-in-depth measure (tRPC Security Advisory).
The advisory was published by tRPC maintainer KATT on December 15, 2025, and credited to researcher Pr00fOf3xpl0it for responsible disclosure. The vulnerability was picked up by standard vulnerability tracking feeds (NVD, ENISA EUVD, Red Hat CVE database, GitLab Advisories) shortly after disclosure, indicating routine industry awareness. No significant broader media coverage or notable social media discussion beyond automated CVE tracking posts has been identified (tRPC Security Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."