High severity7.3NVD Advisory· Published Jan 10, 2022· Updated Jun 17, 2026
CVE-2021-23568
CVE-2021-23568
Description
The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
extend2npm | < 1.0.1 | 1.0.1 |
Affected products
3- extend2/extend2description
Patches
Vulnerability mechanics
References
6- github.com/eggjs/extend2/commit/aa332a59116c8398976434b57ea477c6823054f8nvdPatchThird Party AdvisoryWEB
- github.com/eggjs/extend2/pull/2nvdIssue TrackingPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-EXTEND2-2320315nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-gjm5-83cw-p3p2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23568ghsaADVISORY
- github.com/eggjs/extend2/blob/master/index.js%23L50-L60nvdBroken LinkWEB
News mentions
0No linked articles in our index yet.