CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2021-28860

Critical · CVSS 9.1

mixme (node-mixme) — Prototype Pollution (CWE-1321)

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-1321

Description

In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).

Search profile — drives PoC discovery

Symbols mutate()merge()__proto__mixmenode-mixmeGHSA-79jw-6wg7-r9g4
Keywords CVE-2021-28860mixme prototype pollutionnode-mixme __proto__mixme mutate merge prototypemixme DoSnpm mixme exploitprototype pollution PoC mixme
Versions: < 0.5.1

Affected packages

npm mixme 0 → 0.5.1

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z