CVE-2023-26102: Rangy Project Rangy
High severity, CVSS 8.2. EPSS: 0.8% chance of exploitation in the next 30 days.
All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype
Affected products
- Rangy Project Rangy: affected versions not specified
Published 2023-02-24. Last modified 2026-06-17.