CVE-2026-29063
Immutable.js <3.8.3/4.3.7/5.1.5 - Prototype Pollution
Title source: llmDescription
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
References (4)
Scores
EPSS
0.0005
EPSS Percentile
13.7%
Classification
CWE
CWE-1321
Status
draft
Timeline
Published
Mar 06, 2026
Tracked Since
Mar 07, 2026