Description
A Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs.
Recommendation
Update the immutable package to the latest compatible version. Followings are version details:
Affected version(s): **< 3.8.3 >= 4.0.0-rc.1, < 4.3.8 >= 5.0.0, < 5.1.5** Patched version(s): **3.8.3 4.3.8 5.1.5**
References
Could your website be exposed too?
SmartScanner can check your website for Immutable is vulnerable to Prototype Pollution and gives you actionable findings to investigate.
Start a free scanRelated Issues
- axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge - CVE-2026-44495
- axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` - CVE-2026-44494
- Mermaid Architecture diagrams are vulnerable to prototype pollution - CVE-2026-71437
- lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - CVE-2026-2950
You might also like:
See something that needs correcting? Let us knowUpdated April 24, 2026


