Vulnerabilities (CVE)

Filtered by vendor Merge Project Subscribe
Filtered by product Merge
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-3645 1 Merge Project 1 Merge 2022-07-29 7.5 HIGH 9.8 CRITICAL
merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2020-28499 1 Merge Project 1 Merge 2021-05-17 7.5 HIGH 9.8 CRITICAL
All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge .