GHSA-3jc6-6r48-v6qf

Suggest an improvement
Source
https://github.com/advisories/GHSA-3jc6-6r48-v6qf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-3jc6-6r48-v6qf/GHSA-3jc6-6r48-v6qf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3jc6-6r48-v6qf
Aliases
  • CVE-2026-6594
Published
2026-04-20T03:34:41Z
Modified
2026-04-23T14:32:52.527824Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Deep Merge is Vulnerable to Prototype Pollution Through Lack of Sanitization
Details

A Prototype Pollution vulnerability was determined in brikcss merge up to 1.3.0. Executing a manipulation of the argument proto/constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-23T14:23:26Z",
    "cwe_ids": [
        "CWE-1321",
        "CWE-94"
    ],
    "severity": "MODERATE",
    "nvd_published_at": "2026-04-20T02:16:15Z"
}
References

Affected packages

npm / @brikcss/merge

Package

Name
@brikcss/merge
View open source insights on deps.dev
Purl
pkg:npm/%40brikcss/merge

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.3.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-3jc6-6r48-v6qf/GHSA-3jc6-6r48-v6qf.json"