PT-2021-17969 · Npm · Node.Js Mixme

·

CVE-2021-28860

·

Published

2021-05-03

·

Updated

2026-07-05

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Node.js mixme versions prior to 0.5.1
Description: The issue allows an attacker to add or alter properties of an object via proto through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program, putting the availability of the program at risk and causing a potential denial of service (DoS).
Recommendations: For versions prior to 0.5.1, update to version 0.5.1 or later to resolve the issue. As a temporary workaround, consider disabling the mutate() and merge() functions until a patch is available.

Fix

DoS

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-28860
GHSA-79JW-6WG7-R9G4
GHSA-R5CQ-9537-9RPF

Affected Products

Node.Js Mixme