Vulnerability vector:
- Base vulnerability score (CVSSv4.0): CVSS:4.0/ AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
- Severity (CVSSv4.0): 7.1 (High)
Description:
The vulnerability was identified in Foundry Virtual Tabletop, versions 13.350.
The discovered vulnerability allows an attacker to inject arbitrary properties into the global object prototype of the Foundry Virtual Tabletop (FVT) server via unsafe recursive merge operations on user‑controlled input. This enables the attacker to tamper with the base prototype of JavaScript objects, which can subsequently lead to a range of attacks: denial‑of‑service (DoS) through infinite recursion, authentication bypass and other malicious outcomes.
Vulnerability status: Confirmed by vendor
Date of vulnerability remediation: 12.11.2025
Recommendations:
- Update to version 13.351 or higher
Additional information: Security advisory
Researcher: Oleg Surnin (Positive Technologies)