{"id":"GHSA-r5cq-9537-9rpf","summary":"Prototype Pollution in mixme","details":"Node.js mixme 0.5.0, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).","aliases":["CVE-2021-28860","CVE-2021-29491","GHSA-79jw-6wg7-r9g4"],"modified":"2026-09-10T03:49:12.874649745Z","published":"2022-02-10T23:52:01Z","database_specific":{"nvd_published_at":"2021-05-03T12:15:00Z","cwe_ids":["CWE-1321"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-05-19T21:34:53Z"},"references":[{"type":"WEB","url":"https://github.com/adaltas/node-mixme/security/advisories/GHSA-79jw-6wg7-r9g4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-28860"},{"type":"WEB","url":"https://github.com/adaltas/node-mixme/issues/1"},{"type":"WEB","url":"https://github.com/adaltas/node-mixme/commit/cfd5fbfc32368bcf7e06d1c5985ea60e34cd4028"},{"type":"PACKAGE","url":"https://github.com/adaltas/node-mixme"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20210618-0005"},{"type":"WEB","url":"https://www.npmjs.com/~david"},{"type":"WEB","url":"http://nodejs.com"}],"affected":[{"package":{"name":"mixme","ecosystem":"npm","purl":"pkg:npm/mixme"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.5.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-r5cq-9537-9rpf/GHSA-r5cq-9537-9rpf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"}]}