High severity8.2NVD Advisory· Published Feb 4, 2022· Updated Jun 17, 2026
CVE-2021-23470
CVE-2021-23470
Description
This affects the package putil-merge before 3.8.0. The merge() function does not check the values passed into the argument. An attacker can supply a malicious value by adjusting the value to include the constructor property. Note: This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-PUTILMERGE-1317077
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
putil-mergenpm | < 3.8.0 | 3.8.0 |
Affected products
3- cpe:2.3:a:putil-merge_project:putil-merge:*:*:*:*:*:*:*:*Range: <3.8.0
- putil-merge/putil-mergedescription
Patches
Vulnerability mechanics
References
4- github.com/panates/putil-merge/commit/476d00078dfb2827d7c9ee0f2392c81b864f7bc5nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-PUTILMERGE-2391487nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-4g77-cvgw-grvwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23470ghsaADVISORY
News mentions
0No linked articles in our index yet.