CVE-2025-12758 is an input validation flaw in the JavaScript npm package validator affecting versions prior to 13.15.22. The vulnerability is in the isLength() function, which incorrectly handles Unicode variation selectors, specifically U+FE0E and U+FE0F, during string length evaluation. Because these special Unicode elements are not properly accounted for, an attacker can craft inputs containing large numbers of variation selectors that are perceived by the library as much shorter than their actual size or processing footprint. As a result, applications that rely on isLength() to enforce maximum input length may incorrectly accept oversized data. This can undermine application-layer validation and expose downstream components to truncation, resource exhaustion, or other failures when they process the true input size.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone JavaScript proof-of-concept for CVE-2025-12758 affecting validator.js isLength() in versions prior to 13.15.22. The repo contains 5 files: a README describing the bug, package metadata (package.json and package-lock.json), a .gitignore, and a single executable PoC script (poc.js). The code imports the validator package and performs three console tests: two benign baseline checks and one malicious check using Unicode variation selectors (U+FE0F) appended to the string 'test'. The purpose is to demonstrate that max-length validation can be bypassed when applications trust validator.isLength() on unnormalized attacker input. There is no remote exploitation logic, shell payload, callback, or persistence mechanism; this is a local demonstration script intended to reproduce the bug in a developer environment. The exploit capability is limited to showing an application-layer validation bypass that could be leveraged in real targets where overlong input is security-relevant.
This repository provides a proof-of-concept (POC) exploit for CVE-2025-12758, a vulnerability in the 'validator' npm package (versions < 13.15.22). The vulnerability is due to the isLength() function failing to properly exclude Unicode variation selectors (\uFE0F, \uFE0E) from its length calculation, allowing attackers to bypass input length restrictions. The repository contains five files: a README.md with detailed vulnerability and exploitation information, package.json and package-lock.json specifying the vulnerable validator dependency, a .gitignore, and poc.js, which is the main exploit script. The poc.js script demonstrates the vulnerability by showing that a string padded with Unicode variation selectors is incorrectly accepted as valid input by isLength(), even when it exceeds the intended length limit. No network endpoints or remote attack vectors are present; the exploit is local and targets applications using the vulnerable validator package for input validation. The exploit is a POC and does not include weaponized payloads, but it effectively demonstrates the risk of input validation bypass in affected systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.