Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jc6-6r48-v6qf

Опубликовано: 20 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 7.3

Описание

Deep Merge is Vulnerable to Prototype Pollution Through Lack of Sanitization

A Prototype Pollution vulnerability was determined in brikcss merge up to 1.3.0. Executing a manipulation of the argument proto/constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.

Пакеты

Наименование

@brikcss/merge

npm
Затронутые версииВерсия исправления

<= 1.3.1

Отсутствует

EPSS

Процентиль: 26%
0.00336
Низкий

6.9 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-1321
CWE-94

Связанные уязвимости

CVSS3: 7.3
nvd
4 месяца назад

A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument __proto__/constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 26%
0.00336
Низкий

6.9 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-1321
CWE-94