← Vulnerability feed

Vulnerability record · CVE-2021-26707 · published 2 June 2021

CVE-2021-26707: Merge-deep project merge-deep prototype pollution vulnerability

MMerge Deep Project · Merge Deep

The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.

9.8 CVSS 3.1 Critical EPSS 1.9% · top 21.1% CWE-1321 · Prototype pollution
9.8CVSS 3.1 base score, v2 7.5
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-26707 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2019-13272Linux kernel ptrace credential mishandling allows local root escalationThe Linux kernel before 5.1.17 mishandles credential recording in ptrace_link (kernel/ptrace.c) when a process creates a ptrace relationship, and als…KEVEPSS 52%analysed9.8CVE-2021-23383Handlebarsjs handlebars prototype pollution vulnerabilityThe package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from a…EPSS 4.5%9.8CVE-2021-20231Gnutls use after free vulnerabilityA flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.EPSS 3.8%8.8CVE-2022-21703Grafana cross-site request forgery vulnerabilityGrafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability whic…EPSS 2.3%8.8CVE-2018-3722Merge-deep project merge-deep vulnerabilitymerge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modi…EPSS 2.0%8.7CVE-2022-31097Grafana Unified Alerting stored XSS allows editor-to-admin privilege escalationGrafana 8.x and 9.x branches before 9.0.3, 8.5.9, 8.4.10 and 8.3.10 contain a stored cross-site scripting flaw in the Unified Alerting feature. An at…EPSS 69%analysed8.3CVE-2020-14664Oracle jdk vulnerabilityVulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u251. Difficult to ex…EPSS 4.2%8.3CVE-2020-14583Oracle openjdk vulnerabilityVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2021-26707), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.