VYPR
High severity8.8NVD Advisory· Published Mar 30, 2018· Updated Jun 17, 2026

CVE-2018-3728

CVE-2018-3728

Description

hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
hoeknpm
>= 5.0.0, < 5.0.35.0.3
hoeknpm
< 4.2.14.2.1

Affected products

2
  • ghsa-coords
    Range: >= 5.0.0, < 5.0.3
  • hapi/hoek node modulev5
    Range: Versions before 5.0.3

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.