High severity8.8NVD Advisory· Published Mar 11, 2020· Updated Jun 17, 2026
CVE-2019-10808
CVE-2019-10808
Description
utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
utilitifynpm | < 1.0.3 | 1.0.3 |
Affected products
3- utilitify/utilitifydescription
- cpe:2.3:a:xcritical.software:utilitify:*:*:*:*:*:node.js:*:*Range: <1.0.3
Patches
Vulnerability mechanics
References
5- snyk.io/vuln/SNYK-JS-UTILITIFY-559497nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-9534-h433-2rjfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-10808ghsaADVISORY
- github.com/xcritical-software/utilitify/commit/88d6e27009823338bf319ffb768fe6b08e8ad2d1,ghsaWEB
- github.com/xcritical-software/utilitify/commit/88d6e27009823338bf319ffb768fe6b08e8ad2d1%2Cnvd
News mentions
0No linked articles in our index yet.