CVE-2019-10745
HIGHassign-deep < 0.4.8 - Prototype Pollution via Constructor or __proto__ Payload
Title source: llmDescription
assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload.
References (1)
Core 1
Core References
Exploit, Patch, Third Party Advisory x_refsource_confirm
https://snyk.io/vuln/SNYK-JS-ASSIGNDEEP-450211
Scores
CVSS v3
7.5
EPSS
0.0114
EPSS Percentile
62.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-1321
Status
published
Products (3)
assign-deep_project/assign-deep
1.0.0
assign-deep_project/assign-deep
< 0.4.8
npm/assign-deep
0 - 0.4.8npm
Published
Aug 20, 2019
Tracked Since
Feb 18, 2026