Skip to main content

CVE-2021-23568

7.3
HIGHCVSS v3.1 Base Score
0.50%
LOW RiskEPSS (66th percentile)

The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.

Published: 1/10/2022
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.3HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CVSS v2 Score

7.5

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

0.50%LOW Exploitation Risk
66th percentile

This vulnerability has a 0.50% probability of being exploited in the next 30 days, ranking higher than 66% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-1321)

CVE-2026-34621HIGH 8.6

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

4/11/2026
CVE-2025-66456CRITICAL 9.8

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 through 1.4.16 contain a prototype pollution vulnerability in `mergeDeep` after merging results of two standard schema validations with the same key. Due to the ordering of merging, there must be an any type that is set as a standalone guard, to allow for the `__proto__ prop` to be merged. When combined with GHSA-8vch-m3f4-q8jf this allows for a full RCE by an attacker. This issue is fixed in version 1.4.17. To workaround, remove the `__proto__ key` from body.

12/9/2025
CVE-2025-25014CRITICAL 9.1

A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.

5/6/2025
CVE-2024-12556HIGH 8.7

Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.

4/8/2025
CVE-2024-48910CRITICAL 9.1

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.

10/31/2024

Similar SeverityHIGH