Description
utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
Recommendation
Update the utilitify package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.3
- Patched version(s): 1.0.3
References
Could your website be exposed too?
SmartScanner can check your website for Improperly Controlled Modification of Dynamically-Determined Object Attributes in utilitify and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Improperly Controlled Modification of Dynamically-Determined Object Attributes in vega-util - CVE-2019-10806
- mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes - CVE-2026-41139
- radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') - CVE-2025-48054
- Improperly Controlled Modification of Object Prototype Attributes - Vulnerability


