Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2021-3757: immer library allows attackers to modify sensitive data
CVE-2021-3757 · published 1 day ago
Summary
The immer library has a security flaw that lets attackers change how data is stored in a way that's not supposed to be changed. This could lead to unexpected behavior in your code. To stay secure, update the immer library to the latest version.
What to do
- Update mweststrate immer to version 9.0.6.
- Update immer to version 8.0.1-aikido.2.
- Update rootio @rootio/immer to version 8.0.1-root.io.2.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | mweststrate | immer |
>= 7.0.0, < 9.0.6 Fix: upgrade to 9.0.6
|
| – | immer_project | immer |
<= 9.0.5 cpe:2.3:a:immer_project:immer:*:*:*:*:*:node.js:*:* |
| Root:npm | – | immer |
< 8.0.1-aikido.2 Fix: upgrade to 8.0.1-aikido.2
|
| Root:npm | rootio | @rootio/immer |
< 8.0.1-root.io.2 Fix: upgrade to 8.0.1-root.io.2
|
Original advisory text
CVE-2021-3757 in immer - Patched by Root
Root has patched CVE-2021-3757 in the immer package for Root:npm. Multiple fixed versions available.
Severity
9.8
Critical
CVSS 3.1: 7.5 (GHSA)
Exploitation
EPSS 2%
Type
CWE-915Improperly Controlled Modification of Dynamically-Determined Object Attributes
CWE-1321Prototype Pollution
Timeline
Published2 Sep 2026
Updated2 Sep 2026
First seen6 Mar 2026
Monitor software like this
Free during beta