PT-2021-11555 · Merge · Merge

Published

2021-02-18

·

Updated

2026-06-01

·

CVE-2020-28499

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: merge versions prior to 2.1.1
Description: The issue concerns Prototype Pollution via the recursiveMerge function. This affects the merge package, potentially allowing for malicious modifications to the prototype.
Recommendations: For versions prior to 2.1.1, update to version 2.1.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the recursiveMerge function until a patch is applied.

Fix

Weakness Enumeration

Related Identifiers

CVE-2020-28499
GHSA-7WPW-2HJM-89GP
SNYK-JAVA-ORGWEBJARSNPM-1071049
SNYK-JS-MERGE-1042987

Affected Products

Merge