High severity7.3NVD Advisory· Published Jun 30, 2023· Updated Jun 17, 2026
CVE-2023-26135
CVE-2023-26135
Description
All versions of the package flatnest are vulnerable to Prototype Pollution via the nest() function in the flatnest/nest.js file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
flatnestnpm | <= 1.0.0 | — |
Affected products
3- cpe:2.3:a:flatnest_project:flatnest:*:*:*:*:*:node.js:*:*
- flatnest/flatnestdescription
Patches
Vulnerability mechanics
References
7- github.com/brycebaril/node-flatnest/issues/4nvdExploitIssue TrackingWEB
- security.snyk.io/vuln/SNYK-JS-FLATNEST-3185149nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-7px2-3c2p-q4v4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-26135ghsaADVISORY
- github.com/brycebaril/node-flatnest/blob/b7d97ec64a04632378db87fcf3577bd51ac3ee39/nest.jsghsaWEB
- github.com/brycebaril/node-flatnest/blob/b7d97ec64a04632378db87fcf3577bd51ac3ee39/nest.js%23L43nvdBroken LinkWEB
- github.com/brycebaril/node-flatnest/commit/27d569baf9d9d25677640edeaf2d13af165868d6nvdWEB
News mentions
0No linked articles in our index yet.