Improperly Controlled Modification of Dynamically-Determined Object Attributes in utilitify
- Severity:
- High
Description
utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
Recommendation
Update the utilitify package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.3
- Patched version(s): 1.0.3
References
Related Issues
- Improperly Controlled Modification of Dynamically-Determined Object Attributes in vega-util - CVE-2019-10806
- mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes - CVE-2026-41139
- radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') - CVE-2025-48054
- Improperly Controlled Modification of Object Prototype Attributes - Vulnerability
You might also like:
- Tags:
- npm
- utilitify
Anything's wrong? Let us know Last updated on January 27, 2023


