PT-2026-33688 · Brikcss · Merge

Sudosme

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-6594

CVSS v2.0

7.5

High

AV:N/AC:L/Au:N/C:P/I:P/A:P
A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument proto /constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.

Exploit

Fix

Prototype Pollution

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6594

Affected Products

Merge