{"id":"CVE-2018-3720","details":"assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of \"Object\" via __proto__, causing the addition or modification of an existing property that will exist on all objects.","aliases":["GHSA-xcvv-84j5-jw9h"],"modified":"2026-08-18T11:18:46.447374Z","published":"2018-06-07T02:29:08.270Z","references":[{"type":"FIX","url":"https://github.com/jonschlinkert/assign-deep/commit/19953a8c089b0328c470acaaaf6accdfcb34da11"},{"type":"EVIDENCE","url":"https://hackerone.com/reports/310707"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jonschlinkert/assign-deep","events":[{"introduced":"0"},{"fixed":"24412bd2b59bc128437819c4a4518a7b7148d81a"},{"fixed":"19953a8c089b0328c470acaaaf6accdfcb34da11"}],"database_specific":{"cpe":"cpe:2.3:a:assign-deep_project:assign-deep:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.4.7"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.4.6","0.4.5","0.4.4","0.4.3","0.4.2","0.4.0","0.3.1","0.3.0","0.1.2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-3720.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}