VYPR
High severityOSV Advisory· Published Jul 21, 2026· Updated Jul 23, 2026

CVE-2026-46681

CVE-2026-46681

Description

@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps function in lib/src/object/copy.ts uses for...in to iterate over source object properties without an Object.hasOwnProperty check, and does not filter dangerous keys (__proto__, constructor, prototype). This allows an attacker to pollute the prototype chain of all objects in the application. Version 0.14.0 patches the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@nevware21/ts-utilsnpm
< 0.14.00.14.0

Affected products

2
  • Nevware21/Ts UtilsOSV2 versions
    0.13.0, 0.12.6, 0.12.5, …+ 1 more
    • (no CPE)range: 0.13.0, 0.12.6, 0.12.5, …
    • (no CPE)range: <0.14.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.