The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-06-02T14:24:30

Updated: 2024-08-03T20:33:40.345Z

Reserved: 2021-02-05T00:00:00

Link: CVE-2021-26707

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-06-02T15:15:07.787

Modified: 2022-12-02T19:37:32.077

Link: CVE-2021-26707

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-01-26T00:00:00Z

Links: CVE-2021-26707 - Bugzilla