CVE-2026-29063

Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVSS

No CVSS.

Configurations

No configuration.

History

06 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-06 19:16

Updated : 2026-03-06 19:16


NVD link : CVE-2026-29063

Mitre link : CVE-2026-29063

CVE.ORG link : CVE-2026-29063


JSON object : View

Products Affected

No product.

CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')