CVE-2025-3982 | nortikin Sverchok 1.3.0 Set Property Mk2 Node getsetprop_mk2.py SvSetPropNodeMK2 prototype pollution
A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0. Affected is the function SvSetPropNodeMK2 of the file sverchok/nodes/object_nodes/getsetprop_mk2.py of the component Set Property Mk2 Node. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution').
This vulnerability is traded as CVE-2025-3982. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.