CVE-2026-6621Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in 1024bit extend-deep up to 0.1.6. The impacted element is an unknown function of the file index.js. This manipulation of the argument __proto__ causes improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The code repository of the project has not been active for many years.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-20: 2Technical Details · 2026-04-20: 204-20
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6621 Prototype Pollution Vulnerability in 1024bit extend-deep Up to 0.1.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6621

    Post summary

    The snippet notes CVE-2026-6621 as a prototype‑pollution issue affecting extend-deep up to 0.1.6, but provides no further detail on exploits, mitigation, or real‑world usage.

    0000038
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6621 A vulnerability was determined in 1024bit extend-deep up to 0.1.6. The impacted element is an unknown function of the file index.js. This manipulation of the argument _… https://www.cve.org/CVERecord?id=CVE-2026-6621

    Post summary

    The post announces CVE-2026-6621, describing an issue in the 1024bit extend‑deep library (up to 0.1.6) affecting an unknown function in index.js, and provides a link to the CVE record.

    00000101
    57.2K followersView on X

Explore more