Object Manipulation Vulnerability in Node.js Mixme by Adaltas
CVE-2021-28860
9.1CRITICAL
What is CVE-2021-28860?
In Node.js Mixme versions prior to 0.5.1, a vulnerability allows attackers to manipulate the prototype chain using the __proto__ property via the mutate() and merge() functions. This exploitation can lead to unintended property assignments across objects in the application, potentially jeopardizing the program's availability and resulting in a Denial of Service (DoS) scenario.
