CVE-2023-26102: Rangy Project Rangy

High severity, CVSS 8.2. EPSS: 0.8% chance of exploitation in the next 30 days.

All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype

Affected products

Published 2023-02-24. Last modified 2026-06-17.