CVE-2019-10768

HIGH7.5EPSS 0.41%

angular Prototype Pollution vulnerability

Published: 11/20/2019Modified: 3/13/2026
Also known as:GHSA-89mq-4x47-5v83DEBIAN-CVE-2019-10768

Description

Versions of `angular ` prior to 1.7.9 are vulnerable to prototype pollution. The deprecated API function `merge()` does not restrict the modification of an Object's prototype in the , which may allow an attacker to add or modify an existing property that will exist on all objects. ## Recommendation Upgrade to version 1.7.9 or later. The function was already deprecated and upgrades are not expected to break functionality.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References (8)