CVE-2019-10808: Xcritical.software Utilitify

High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.

utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.

Affected products

Published 2020-03-11. Last modified 2026-06-17.