{"id":"CVE-2018-3719","details":"mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of \"Object\" via __proto__, causing the addition or modification of an existing property that will exist on all objects.","aliases":["GHSA-3mpr-hq3p-49h9"],"modified":"2026-07-08T20:14:44.473769Z","published":"2018-06-07T02:29:08.223Z","references":[{"type":"FIX","url":"https://github.com/jonschlinkert/mixin-deep/commit/578b0bc5e74e14de9ef4975f504dc698796bdf9c"},{"type":"EVIDENCE","url":"https://hackerone.com/reports/311236"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jonschlinkert/mixin-deep","events":[{"introduced":"0"},{"fixed":"a4bcf3ef9cdc144c4c39ff8f1e1f566f338c477e"},{"fixed":"578b0bc5e74e14de9ef4975f504dc698796bdf9c"}],"database_specific":{"cpe":"cpe:2.3:a:mixin-deep_project:mixin-deep:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.3.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.3.0","1.2.0","1.1.3","1.1.2","1.1.0","1.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-3719.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}