
Where Severity Scores Go Wrong: “Just Add Prototype Pollution”
JFrog’s Security Research team consistently tracks and evaluates newly disclosed CVEs in the open-source ecosystem. Their findings reveal that often, the severity scores assigned to vulnerabilities do not accurately reflect their actual impact or risk of exploitation. In 2025, JFrog researchers reviewed critical-severity vulnerabilities from the National Vulnerability Database (NVD) and determined that 96% of these scores were misaligned with the vulnerabilities’ true severity.










