Vulnerability record · CVE-2021-26707 · published 2 June 2021
CVE-2021-26707: Merge-deep project merge-deep prototype pollution vulnerability
MMerge Deep Project · Merge Deep
The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.
Description
The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/jonschlinkert/merge-deep/commit/11e5dd56de8a6aed0b1ed022089dbce6968d82a5 | PatchThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20210716-0008/ | Third Party Advisory |
| https://securitylab.github.com/advisories/GHSL-2020-160-merge-deep/ | Third Party Advisory |
| https://www.npmjs.com/package/merge-deep | ProductThird Party Advisory |
| https://github.com/jonschlinkert/merge-deep/commit/11e5dd56de8a6aed0b1ed022089dbce6968d82a5 | PatchThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20210716-0008/ | Third Party Advisory |
| https://securitylab.github.com/advisories/GHSL-2020-160-merge-deep/ | Third Party Advisory |
| https://www.npmjs.com/package/merge-deep | ProductThird Party Advisory |
Track CVE-2021-26707 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-26707), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.