VDB
DEBIAN-CVE-2026-29063
DEBIAN-CVE-2026-29063
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | node-immutable | 4.3.8-2, 4.3.8-1, 4.3.4-1 |
| Debian:11 | node-immutable | 4.3.8-2, 4.0.0-1, 0 |
| Debian:13 | node-immutable | 4.3.8-1, 4.3.8-2, 4.3.4-1 |
| Debian:14 | node-immutable | 4.3.4-1, 0, 4.3.4-1 |
Exploit Intelligence
- pnpm-workspace.yaml (github-poc)
- netobserv.yaml (github-poc)
- supply-chain-policy.ts (github-poc)
- new-rules.test.ts (github-poc)
- prototype-pollution.js (github-poc)
Timeline
- Mar 6, 2026 CVE Published
- Apr 28, 2026 CVE Updated