CVE-2025-68130: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2025-68130 is a prototype pollution vulnerability in the @trpc/server npm package, specifically within the formDataToObject function used by the Next.js App Router adapter. It affects @trpc/server versions >=10.27.0 and <10.45.3, and >=11.0.0 and <11.8.0, and is only exploitable when using the experimental_caller or experimental_nextAppDirCaller features. The vulnerability was published on December 15–16, 2025, with fixes released in versions 10.45.3 and 11.8.0. It carries a CVSS v4 base score of 8.5 (High) (GitHub Advisory, tRPC Security Advisory).

Technical details

The root cause is classified as CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes — Prototype Pollution). The vulnerable set() function in formDataToObject.ts recursively processes FormData field names using bracket/dot notation (e.g., user[name]) to build nested objects, but performs no validation or sanitization of dangerous keys such as __proto__, constructor, or prototype. When the Next.js App Router adapter receives a FormData input and calls formDataToObject(), an attacker with low-level access can submit field names like __proto__[isAdmin] to directly modify Object.prototype, affecting all subsequently created objects in the Node.js process. A public proof-of-concept demonstrating the attack is included in the official advisory (tRPC Security Advisory, GitHub Advisory).

Impact

Successful exploitation can lead to authorization bypass, denial of service, and data integrity compromise. Because Object.prototype is shared across the entire JavaScript runtime, polluting it with attacker-controlled properties (e.g., isAdmin: "true") causes all objects in the application to inherit those properties, potentially granting unauthorized administrative access. Additionally, overwriting built-in prototype methods such as toString with non-function values can crash the application, causing denial of service. The vulnerability affects both the vulnerable system and subsequent systems, with high integrity impact in both scopes (tRPC Security Advisory, GitHub Advisory).

Exploitability

A public proof-of-concept exploit is available in the official GitHub Security Advisory, demonstrating the attack against @trpc/server@11.7.2. As of the time of disclosure, there is no evidence of active in-the-wild exploitation, and no threat actor attribution has been reported. The EPSS score is approximately 0.19% (41st percentile), indicating a relatively low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Identify target: Locate a Next.js application using @trpc/server versions >=10.27.0 and <10.45.3 or >=11.0.0 and <11.8.0 with experimental_caller or experimental_nextAppDirCaller enabled and normalizeFormData active.
  2. Craft malicious FormData: Construct a FormData payload with field names designed to pollute Object.prototype:
const formData = new FormData();
formData.append("__proto__[isAdmin]", "true");
formData.append("__proto__[role]", "superadmin");
formData.append("username", "attacker");
  1. Submit to tRPC endpoint: Send the crafted FormData as a POST request to a tRPC mutation endpoint handled by the Next.js App Router adapter (e.g., a Server Action route).
  2. Trigger vulnerable code path: The nextAppDirCaller adapter detects input instanceof FormData and calls formDataToObject(input), which splits __proto__[isAdmin] into ["__proto__", "isAdmin"] and recursively sets Object.prototype.isAdmin = "true".
  3. Achieve authorization bypass: Any subsequent authorization check in the application that evaluates user.isAdmin or similar properties will now return "true" for all objects, granting the attacker elevated privileges.
  4. Optional DoS: Alternatively, submit __proto__[toString] with a non-function value to crash the application on any subsequent .toString() call (tRPC Security Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unusual HTTP POST requests to tRPC/Next.js Server Action endpoints containing FormData field names with __proto__, constructor, or prototype patterns (e.g., __proto__[isAdmin], constructor[prototype][role]).
  • Logs: Server-side application logs showing unexpected property values on plain objects (e.g., isAdmin: true on objects that should not have this property); Node.js error logs referencing TypeError on built-in methods like toString or hasOwnProperty if DoS payload was used.
  • Application Behavior: Sudden privilege escalation events where unprivileged users gain administrative access; unexpected crashes or TypeError exceptions in the Node.js process following form submissions.
  • Process: Anomalous behavior in the Next.js server process after processing FormData inputs, such as unexpected admin-level operations performed by low-privilege accounts (tRPC Security Advisory).

Mitigation and workarounds

Upgrade @trpc/server to version 10.45.3 (for the v10 branch) or 11.8.0 (for the v11 branch), which fix the issue by adding validation of dangerous prototype keys in formDataToObject (GitHub Advisory). If an immediate upgrade is not possible, disable experimental_caller / experimental_nextAppDirCaller in your tRPC configuration to eliminate the vulnerable code path. Additionally, implement server-side input validation to reject FormData field names containing __proto__, constructor, or prototype as a defense-in-depth measure (tRPC Security Advisory).

Community reactions

The advisory was published by tRPC maintainer KATT on December 15, 2025, and credited to researcher Pr00fOf3xpl0it for responsible disclosure. The vulnerability was picked up by standard vulnerability tracking feeds (NVD, ENISA EUVD, Red Hat CVE database, GitLab Advisories) shortly after disclosure, indicating routine industry awareness. No significant broader media coverage or notable social media discussion beyond automated CVE tracking posts has been identified (tRPC Security Advisory, GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management