Loading HuntDB...

GHSA-3mpr-hq3p-49h9

GitHub Security Advisory

Prototype Pollution in mixin-deep

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Versions of `mixin-deep` before 1.3.1 are vulnerable to prototype pollution via merging functions.

## Recommendation

Update to version 1.3.1 or later.

Affected Packages

npm mixin-deep
Affected versions: 0 (fixed in 1.3.1)

Related CVEs

Key Information

GHSA ID
GHSA-3mpr-hq3p-49h9
Published
July 26, 2018 3:10 PM
Last Modified
March 1, 2023 1:32 AM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
mixin-deep
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 3, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.