← Back

Rangy

rangy

Vendor: Rangy Project • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rangy Project
1Rangy
Jun 17, 2026
Feb 24, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Obje...Show more
All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype Show less