EXPOSURES › CVE-2021-28860
CVE-2021-28860
CRITICAL
DETAIL
SourceNVD · cve
Published2021-05-03
CVSS9.1
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-28860 ↗
⚡ RCE
SHAME 50/100
rce
In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at ri
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.80
CISA KEV inclusion indicates critical severity and active exploitation, though vendor response details are absent in provided sources.
severe-fallout
"U.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog"
severe-fallout
"Active Exploitation Alert: Critical CVE-2026-20896 Authentication Bypass in Gitea Docker Image Exposes Repositories and Secrets"
severe-fallout
"Security researchers are warning organizations using Gitea act_runner with the Docker backend to review their deployments after proof-of-concept (PoC) code for CVE-2026-58053 was publicly released"
neutral
"CVE-2021-28860: In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions."
neutral
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.