CVE-2026-29063Disclosure(immutable-js / immutable)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321CWE-915

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • immutable

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-06); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Products
immutable

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-06: 3Mentions · 2026-03-24: 2Technical Details · 2026-03-06: 2Technical Details · 2026-03-24: 203-0603-24
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-063
Disclosure3
2026-03-242
Disclosure2
Full discourse5 posts
  • Matthias Knäpper@knaepp
    Disclosure

    IBM WebSphere Application Server Liberty is affected by a prototype pollution vulnerability due to immutable (CVE-2026-29063) https://tinyurl.com/25lyxhlz

    Post summary

    CVE-2026-29063 is a prototype‑pollution vulnerability affecting IBM WebSphere Application Server Liberty, but the tweet offers no evidence of active exploitation, PoCs, or remediation guidance.

    0000029
    108 followersView on X
  • Matthias Knäpper@knaepp
    Disclosure

    PH70510:WebSphere Liberty is affected by a prototype pollution vulnerability due to immutable (CVE-2026-29063 CVSS 8.7) https://tinyurl.com/27tvd2v2

    Post summary

    WebSphere Liberty is reported to have a prototype‑pollution flaw (CVE‑2026‑29063) with a CVSS score of 8.7; no PoC, exploit, or patch information is disclosed.

    0000026
    108 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29063 Prototype Pollution Vulnerability in Immutable.js Before 3.8.3, 4.3.7, and 5.1.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29063

    Post summary

    A new prototype pollution vulnerability was disclosed for Immutable.js versions prior to 3.8.3, 4.3.7, and 5.1.5, with no additional details about proof‑of‑concept, exploit, or patch provided.

    0000062
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29063 Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the merge… https://www.cve.org/CVERecord?id=CVE-2026-29063

    Post summary

    The provided text announces CVE‑2026‑29063 as a Prototype Pollution flaw in Immutable.js affecting specific versions, with no evidence of PoC, exploit, active attacks, or patches disclosed.

    00000104
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-29063 - Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable Intel Report: https://ift.tt/BY5lQGv

    Post summary

    The alert announces CVE-2026-29063, a prototype‑pollution flaw in Immutable.js, but provides no PoC, exploit, or patch information.

    0000025
    343 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appimmutable-jsimmutable-node.js-

Explore more