Vulnerabilities/

Immutable is vulnerable to Prototype Pollution

Severity:
High

Description

A Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs.

Recommendation

Update the immutable package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
immutable
Anything's wrong? Let us know Last updated on March 06, 2026