Critical severity9.8NVD Advisory· Published Jun 2, 2021· Updated Jun 17, 2026
CVE-2021-26707
CVE-2021-26707
Description
The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
merge-deepnpm | < 3.0.3 | 3.0.3 |
Affected products
4- cpe:2.3:a:merge-deep_project:merge-deep:*:*:*:*:*:node.js:*:*Range: <3.0.3
- cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:*
- Node.js/merge-deepdescription
Patches
Vulnerability mechanics
References
8- github.com/jonschlinkert/merge-deep/commit/11e5dd56de8a6aed0b1ed022089dbce6968d82a5nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-r6rj-9ch6-g264ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-26707ghsaADVISORY
- security.netapp.com/advisory/ntap-20210716-0008/nvdThird Party Advisory
- securitylab.github.com/advisories/GHSL-2020-160-merge-deepghsaADVISORY
- securitylab.github.com/advisories/GHSL-2020-160-merge-deep/nvdThird Party Advisory
- www.npmjs.com/package/merge-deepnvdProductThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20210716-0008ghsaWEB
News mentions
0No linked articles in our index yet.