-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| web3-utils | npm | >= 4.0.1, < 4.2.1 | 4.2.1 |
The GitHub advisory explicitly identifies mergeDeep as vulnerable, corroborated by the commit diff showing a fix in objects.ts. Snyk and NVD reports also list the format() function as vulnerable, with a PoC demonstrating exploitation. While the commit only addresses mergeDeep, multiple authoritative sources (Snyk, NVD) confirm both functions are entry points for the vulnerability. The confidence is high due to explicit mentions in advisories and reproducible exploitation steps.
Ongoing coverage of React2Shell