CVE Database
/

CVE-2026-29063

Back to search

CVE-2026-29063

Published: Mar 6, 2026

Modified: Mar 6, 2026

PUBLISHED

Description

Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.

VendorProductVersions

immutable-js

immutable-js

affected
< 3.8.3
affected
< 4.3.7
affected
< 5.1.5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now