VYPR
High severity7.5NVD Advisory· Published Aug 20, 2019· Updated Jun 17, 2026

CVE-2019-10745

CVE-2019-10745

Description

assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
assign-deepnpm
< 0.4.80.4.8
assign-deepnpm
>= 1.0.0, < 1.0.11.0.1

Affected products

3
  • cpe:2.3:a:assign-deep_project:assign-deep:*:*:*:*:*:node.js:*:*+ 1 more
    • cpe:2.3:a:assign-deep_project:assign-deep:*:*:*:*:*:node.js:*:*range: <0.4.8
    • cpe:2.3:a:assign-deep_project:assign-deep:1.0.0:*:*:*:*:node.js:*:*
  • ghsa-coords
    Range: < 0.4.8

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.