Loading HuntDB...

GHSA-r96c-57pf-9jjm

GitHub Security Advisory

Prototype Pollution in node.extend

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

Versions of `node.extend` before 1.1.7 or 2.0.1 are vulnerable to prototype pollution.

## Recommendation

Update to version 1.1.7, 2.0.1 or later.

Affected Packages

npm node.extend
Affected versions: 0 (fixed in 1.1.7)
npm node.extend
Affected versions: 2.0.0 (fixed in 2.0.1)

Related CVEs

Key Information

GHSA ID
GHSA-r96c-57pf-9jjm
Published
February 7, 2019 6:17 PM
Last Modified
September 12, 2023 6:31 PM
CVSS Score
9.0 /10
Primary Ecosystem
npm
Primary Package
node.extend
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 1, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.