CVE-2021-28860
Critical · CVSS 9.1mixme (node-mixme) — Prototype Pollution (CWE-1321)
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-1321
Description
In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).
Search profile — drives PoC discovery
Symbols mutate()merge()__proto__mixmenode-mixmeGHSA-79jw-6wg7-r9g4
Keywords CVE-2021-28860mixme prototype pollutionnode-mixme __proto__mixme mutate merge prototypemixme DoSnpm mixme exploitprototype pollution PoC mixme
Versions: < 0.5.1
Affected packages
| npm | mixme | 0 → 0.5.1 |
References
- https://github.com/adaltas/node-mixme/commit/cfd5fbfc32368bcf7e06d1c5985ea60e34cd4028
- https://github.com/adaltas/node-mixme/issues/1
- https://github.com/adaltas/node-mixme/security/advisories/GHSA-79jw-6wg7-r9g4
- https://security.netapp.com/advisory/ntap-20210618-0005/
- https://www.npmjs.com/~david
- http://nodejs.com
- https://github.com/adaltas/node-mixme/commit/cfd5fbfc32368bcf7e06d1c5985ea60e34cd4028
- https://github.com/adaltas/node-mixme/issues/1
- https://github.com/adaltas/node-mixme/security/advisories/GHSA-79jw-6wg7-r9g4
- https://security.netapp.com/advisory/ntap-20210618-0005/
- https://www.npmjs.com/~david
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z