CVE-2019-10745

HIGH

assign-deep < 0.4.8 - Prototype Pollution via Constructor or __proto__ Payload

Title source: llm
STIX 2.1

Description

assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload.

References (1)

Core 1
Core References
Exploit, Patch, Third Party Advisory x_refsource_confirm
https://snyk.io/vuln/SNYK-JS-ASSIGNDEEP-450211

Scores

CVSS v3 7.5
EPSS 0.0114
EPSS Percentile 62.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-1321
Status published
Products (3)
assign-deep_project/assign-deep 1.0.0
assign-deep_project/assign-deep < 0.4.8
npm/assign-deep 0 - 0.4.8npm
Published Aug 20, 2019
Tracked Since Feb 18, 2026