VYPR
Critical severity9.8NVD Advisory· Published Mar 6, 2026· Updated Apr 17, 2026

CVE-2026-29063

CVE-2026-29063

Description

Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
immutablenpm
>= 4.0.0-rc.1, < 4.3.84.3.8
immutablenpm
>= 5.0.0, < 5.1.55.1.5
immutablenpm
< 3.8.33.8.3

Affected products

15

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.