cbcvebase.
CVE-2018-3719
published 2018-06-07

CVE-2018-3719: mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the…

PriorityP346high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.12%
80.0th percentile
mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

Affected

5 ranges
VendorProductVersion rangeFixed in
debiannode-mixin-deep< node-mixin-deep 1.1.3-2 (bookworm)node-mixin-deep 1.1.3-2 (bookworm)
hackeronemixin-deep_node_module
mixin-deep_projectmixin-deep< 1.3.11.3.1
mixin-deep_projectmixin-deep>= 0 < 1.3.11.3.1
muttmutt>= 0 < 1.5.24-1ubuntu0.21.5.24-1ubuntu0.2

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.