A vulnerability was found in colorjs color-name 2.0.1. It has been classified as critical. Impacted is an unknown function. This manipulation causes embedded malicious code. This vulnerability is registered as CVE-2025-59145. Remote exploitation of the attack is possible. No exploit is available. Upgrading the affected component is recommended. Weiterlesen: CVE-2025-59145 | colorjs color-name 2.0.1 malicious code (ID 1005)
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2025-59145 | colorjs color-name 2.0.1 malicious code (ID 1005)
A vulnerability was found in colorjs color-name 2.0.1. It has been classified as critical. Impacted is an unknown function. This manipulation causes embedded…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
CISA-SSVC-Triage (vulnrichment)CVE-2025-59145
Exploitation: none (Keine bekannte Ausnutzung)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2025-09-15T20:39:50.044627Z · CISA Coordinator
Advisory Radar
In herstellerseitiger Prüfung
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
-
Web Referencesocket.dev
-
Web Referencewww.aikido.dev
-
Web Referencewww.ox.security