CVE-2025-31475 | AmauriC tarteaucitron.js up to 1.20.0 addOrUpdate prototype pollution (GHSA-4hwx-xcc5-2hfc)
A vulnerability, which was classified as problematic, was found in AmauriC tarteaucitron.js up to 1.20.0. Affected is the function addOrUpdate. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution').
This vulnerability is traded as CVE-2025-31475. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.