CVE-2026-29063
published 2026-03-06CVE-2026-29063: Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.98%
60.1th percentile
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-immutable | < node-immutable 4.3.8-1 (forky) | node-immutable 4.3.8-1 (forky) |
| immutable-js | immutable | >= 3.0.0 < 3.8.3 | 3.8.3 |
| immutable-js | immutable | >= 4.0.0 < 4.3.7 | 4.3.7 |
| immutable-js | immutable | >= 5.0.0 < 5.1.5 | 5.1.5 |
| immutable-js | immutable-js | < 3.8.3 | 3.8.3 |
| immutable-js | immutable-js | < 4.3.7 | 4.3.7 |
| immutable-js | immutable-js | < 5.1.5 | 5.1.5 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.7HIGH
vendor_debian8.7HIGH
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution
vendor_redhat·2026-03-06·CVSS 8.7
CVE-2026-29063 [HIGH] CWE-915 immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution
immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
A flaw was found in Immutable.js, a library for persistent immutable data structures. This vulnerability, known as Prototype Pollution, allows an attacker with low privileges to inject unwanted properties into core JavaScript object prototypes without user interaction. By manipulating specific APIs such as mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject(), a remote attacker could potentially exec
Debian
CVE-2026-29063: node-immutable - Immutable.js provides many Persistent Immutable data structures. Prior to versio...
vendor_debian·2026·CVSS 8.7
CVE-2026-29063 [HIGH] CVE-2026-29063: node-immutable - Immutable.js provides many Persistent Immutable data structures. Prior to versio...
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 4.3.8-1)
sid: resolved (fixed in 4.3.8-1)
trixie: open
OSV
CVE-2026-29063: Immutable
osv·2026-03-06·CVSS 8.7
CVE-2026-29063 [HIGH] CVE-2026-29063: Immutable
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
OSV
Immutable is vulnerable to Prototype Pollution
osv·2026-03-04
CVE-2026-29063 [HIGH] Immutable is vulnerable to Prototype Pollution
Immutable is vulnerable to Prototype Pollution
## Impact
_What kind of vulnerability is it? Who is impacted?_
A Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs.
## Affected APIs
| API | Notes |
| --------------------------------------- | ----------------------------------------------------------- |
| `mergeDeep(target, source)` | Iterates source keys via `ObjectSeq`, assigns `merged[key]` |
| `mergeDeepWith(merger, target, source)` | Same code path |
| `merge(target, source)` | Shallow variant, same assignment logic |
| `Map.toJS()` | `object[k] = v` in `toObject()` with no `__proto__` guard |
| `Map.toObject()` | Same `toObject()` implementation |
| `Map.mergeDeep(source)` | When source is converted to pla
GHSA
Immutable is vulnerable to Prototype Pollution
ghsa·2026-03-04
CVE-2026-29063 [HIGH] CWE-1321 Immutable is vulnerable to Prototype Pollution
Immutable is vulnerable to Prototype Pollution
## Impact
_What kind of vulnerability is it? Who is impacted?_
A Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs.
## Affected APIs
| API | Notes |
| --------------------------------------- | ----------------------------------------------------------- |
| `mergeDeep(target, source)` | Iterates source keys via `ObjectSeq`, assigns `merged[key]` |
| `mergeDeepWith(merger, target, source)` | Same code path |
| `merge(target, source)` | Shallow variant, same assignment logic |
| `Map.toJS()` | `object[k] = v` in `toObject()` with no `__proto__` guard |
| `Map.toObject()` | Same `toObject()` implementation |
| `Map.mergeDeep(source)` | When source is converted to pla
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-29063 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-29063 [HIGH] CVE-2026-29063 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-29063 :
JavaScript vulnerability analysis and mitigation
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
Source : NVD
## 8.7
Score
Published March 6, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
JavaScript
Grafana
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.2
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
gjs-devel
grafana-elasticsearch
Sources
NVD
Chainguard Has Fix Added at: Ma
Bugzilla
CVE-2026-29063 mozjs78: Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable [epel-all]
bugzilla·2026-03-24·CVSS 8.7
CVE-2026-29063 [HIGH] CVE-2026-29063 mozjs78: Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable [epel-all]
CVE-2026-29063 mozjs78: Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Closing CVE bug as not relevant to the mozjs package, and there is sadly no option to opt out from these reports :( .
Bugzilla
CVE-2026-29063 grafana: Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable [fedora-all]
bugzilla·2026-03-24·CVSS 9.8
CVE-2026-29063 [CRITICAL] CVE-2026-29063 grafana: Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable [fedora-all]
CVE-2026-29063 grafana: Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.
Bugzilla
CVE-2026-29063 immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution
bugzilla·2026-03-06·CVSS 8.7
CVE-2026-29063 [HIGH] CVE-2026-29063 immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution
CVE-2026-29063 immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
https://github.com/immutable-js/immutable-js/releases/tag/v3.8.3https://github.com/immutable-js/immutable-js/releases/tag/v4.3.8https://github.com/immutable-js/immutable-js/releases/tag/v5.1.5https://github.com/immutable-js/immutable-js/security/advisories/GHSA-wf6x-7x77-mvgwhttps://access.redhat.com/errata/RHSA-2026:11070https://access.redhat.com/errata/RHSA-2026:11217https://access.redhat.com/errata/RHSA-2026:11414https://access.redhat.com/errata/RHSA-2026:11858https://access.redhat.com/errata/RHSA-2026:11916https://access.redhat.com/errata/RHSA-2026:12118https://access.redhat.com/errata/RHSA-2026:13542https://access.redhat.com/errata/RHSA-2026:13548https://access.redhat.com/errata/RHSA-2026:13791https://access.redhat.com/errata/RHSA-2026:13826https://access.redhat.com/errata/RHSA-2026:13829https://access.redhat.com/errata/RHSA-2026:13847https://access.redhat.com/errata/RHSA-2026:13853https://access.redhat.com/errata/RHSA-2026:17469https://access.redhat.com/errata/RHSA-2026:17598https://access.redhat.com/errata/RHSA-2026:19375https://access.redhat.com/errata/RHSA-2026:19409https://access.redhat.com/errata/RHSA-2026:19410https://access.redhat.com/errata/RHSA-2026:19712https://access.redhat.com/errata/RHSA-2026:20034https://access.redhat.com/errata/RHSA-2026:20041https://access.redhat.com/errata/RHSA-2026:20042https://access.redhat.com/errata/RHSA-2026:20088https://access.redhat.com/errata/RHSA-2026:21657https://access.redhat.com/errata/RHSA-2026:21658https://access.redhat.com/errata/RHSA-2026:21703https://access.redhat.com/errata/RHSA-2026:21931https://access.redhat.com/errata/RHSA-2026:22465https://access.redhat.com/errata/RHSA-2026:23246https://access.redhat.com/errata/RHSA-2026:24473https://access.redhat.com/errata/RHSA-2026:24977https://access.redhat.com/errata/RHSA-2026:26225https://access.redhat.com/errata/RHSA-2026:26232https://access.redhat.com/errata/RHSA-2026:27063https://access.redhat.com/errata/RHSA-2026:28893https://access.redhat.com/errata/RHSA-2026:28964https://access.redhat.com/errata/RHSA-2026:29857https://access.redhat.com/errata/RHSA-2026:29864https://access.redhat.com/errata/RHSA-2026:34049https://access.redhat.com/errata/RHSA-2026:34099https://access.redhat.com/errata/RHSA-2026:34100https://access.redhat.com/errata/RHSA-2026:34342https://access.redhat.com/errata/RHSA-2026:36621https://access.redhat.com/errata/RHSA-2026:36651https://access.redhat.com/errata/RHSA-2026:36882https://access.redhat.com/errata/RHSA-2026:40022https://access.redhat.com/errata/RHSA-2026:40118https://access.redhat.com/errata/RHSA-2026:40945https://access.redhat.com/errata/RHSA-2026:40984https://access.redhat.com/errata/RHSA-2026:41928https://access.redhat.com/errata/RHSA-2026:41941https://access.redhat.com/errata/RHSA-2026:41944https://access.redhat.com/errata/RHSA-2026:6428https://access.redhat.com/errata/RHSA-2026:6568https://access.redhat.com/errata/RHSA-2026:6720https://access.redhat.com/errata/RHSA-2026:6926https://access.redhat.com/errata/RHSA-2026:7329https://access.redhat.com/errata/RHSA-2026:8218https://access.redhat.com/errata/RHSA-2026:8483https://access.redhat.com/errata/RHSA-2026:8484https://access.redhat.com/errata/RHSA-2026:8490https://access.redhat.com/errata/RHSA-2026:8491https://access.redhat.com/errata/RHSA-2026:8493https://access.redhat.com/errata/RHSA-2026:9742https://access.redhat.com/errata/RHSA-2026:9848https://access.redhat.com/security/cve/CVE-2026-29063https://bugzilla.redhat.com/show_bug.cgi?id=2445291https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29063.json
2026-03-06
Published