mediumCVSS 7.3Vulnerability

CVE-2026-6594

A Prototype Pollution vulnerability was determined in brikcss merge up to 1.3.0. Executing a manipulation of the argument __proto__/constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

severity
medium
summary
Deep Merge is Vulnerable to Prototype Pollution Through Lack of Sanitization
epss_score
0.00336
cvss_score
7.3
ghsa_published
2026-04-20T03:34:41Z
source_url
https://github.com/advisories/GHSA-3jc6-6r48-v6qf
ghsa_updated
2026-04-23T14:23:27Z
ghsa_id
GHSA-3jc6-6r48-v6qf
cve_id
CVE-2026-6594
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.26297

Related Entities (6)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]npm/@brikcss/merge

AFFECTS (1)

[Software]npm/@brikcss/merge

HAS_WEAKNESS (2)

[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
[Weakness]Improper Control of Generation of Code ('Code Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph