Feed/CVE-2018-3750
CVE-2018-3750CRITICALCVSS 9.8

CVE-2018-3750

Published Jul 3, 2018·Updated Jun 16, 2026

NVD Description

The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

Public Exploits & PoCs2 found

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free