EXPOSURES › CVE-2026-29063
CVE-2026-29063
CRITICAL
DETAIL
SourceNVD · cve
Published2026-03-06
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-29063 ↗
⚡ RCE
SHAME 50/100
rce
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.