Junglewise Threat Intelligence

CVE-2026-6594: Deep Merge is Vulnerable to Prototype Pollution Through Lack of Sanitization

CVE-2026-6594 · Severity: high · CVSS 7.3 · Published 2026-04-20

Vendors: npm.

Executive brief

The brikcss merge library is a utility used to combine nested objects and arrays in JavaScript applications. A prototype pollution vulnerability allows attackers to inject malicious properties into the JavaScript object prototype by crafting specially-formed merge operations, potentially leading to unauthorized privilege escalation, denial of service, or unexpected application behavior across all objects in the system.

Technical details

This is a prototype pollution vulnerability (CWE-1321, CWE-94) in the @brikcss/merge package affecting versions up to 1.3.0. The root cause is the absence of sanitization for dangerous object keys during recursive merging of objects and arrays. An attacker with network access can trigger the vulnerability by merging a malicious object containing __proto__, constructor.prototype, or prototype keys, which allows modification of Object.prototype attributes. This can lead to unauthorized property injection affecting all JavaScript objects in the application context, enabling privilege escalation (e.g., injecting isAdmin flags), denial of service (by overriding critical methods), or potentially remote code execution in combination with other vulnerabilities. The vendor was reportedly contacted but did not respond. No patch availability information is confirmed in the advisory.

Affected products

  • brikcss @brikcss/merge up to 1.3.1

Timeline

  • 2026-04-20: disclosed
  • 2026-04-23: advisory: GitHub reviewed advisory published

References