Critical severity9.8NVD Advisory· Published Jun 30, 2022· Updated Jun 17, 2026
CVE-2021-40663
CVE-2021-40663
Description
deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:deep.assign_project:deep.assign:0.0.0:alpha0:*:*:*:node.js:*:*
- deep.assign/deep.assigndescription
- ghsa-coords
Patches
Vulnerability mechanics
References
6- github.com/janbialostok/deep-assign/issues/1nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-3829-mgmw-jcg4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-40663ghsaADVISORY
- security.netapp.com/advisory/ntap-20220826-0002/nvdThird Party Advisory
- www.npmjs.com/package/deep.assignnvdProductThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20220826-0002ghsaWEB
News mentions
0No linked articles in our index yet.