CVE-2019-10808: Xcritical.software Utilitify
High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.
utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
Affected products
- Xcritical.software Utilitify: before 1.0.3 (fixed in 1.0.3)
Published 2020-03-11. Last modified 2026-06-17.