Skip to content
COOEY

EXPOSURES › CVE-2021-28860

CVE-2021-28860

CRITICAL
DETAIL
SourceNVD · cve Published2021-05-03 CVSS9.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-28860 ↗
⚡ RCE SHAME 50/100 rce

In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at ri

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
CISA KEV inclusion indicates critical severity and active exploitation, though vendor response details are absent in provided sources.
securityaffairs.com ↗ severe-fallout -0.90
severe-fallout
"U.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog"
www.rescana.com ↗ severe-fallout -0.90
severe-fallout
"Active Exploitation Alert: Critical CVE-2026-20896 Authentication Bypass in Gitea Docker Image Exposes Repositories and Secrets"
CISA ↗ severe-fallout -0.90
severe-fallout
"ICS Advisories | CISA"
dailysecurityreview.com ↗ severe-fallout -0.80
severe-fallout
"Security researchers are warning organizations using Gitea act_runner with the Docker backend to review their deployments after proof-of-concept (PoC) code for CVE-2026-58053 was publicly released"
cooey ↗ severe-fallout -0.50
neutral
"CVE-2021-28860: In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions."
www.cvefind.com ↗ severe-fallout +0.00
neutral
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
app.opencve.io ↗ severe-fallout +0.00
neutral
"CVEs and Security Vulnerabilities - OpenCVE"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.