Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2021-3757: immer library allows attackers to modify sensitive data

CVE-2021-3757 · published 1 day ago
Summary

The immer library has a security flaw that lets attackers change how data is stored in a way that's not supposed to be changed. This could lead to unexpected behavior in your code. To stay secure, update the immer library to the latest version.

What to do
  • Update mweststrate immer to version 9.0.6.
  • Update immer to version 8.0.1-aikido.2.
  • Update rootio @rootio/immer to version 8.0.1-root.io.2.
Affected software
Ecosystem VendorProductAffected versions
npm mweststrate immer >= 7.0.0, < 9.0.6
Fix: upgrade to 9.0.6
immer_project immer <= 9.0.5
cpe:2.3:a:immer_project:immer:*:*:*:*:*:node.js:*:*
Root:npm immer < 8.0.1-aikido.2
Fix: upgrade to 8.0.1-aikido.2
Root:npm rootio @rootio/immer < 8.0.1-root.io.2
Fix: upgrade to 8.0.1-root.io.2
Original advisory text
CVE-2021-3757 in immer - Patched by Root
Root has patched CVE-2021-3757 in the immer package for Root:npm. Multiple fixed versions available.
Severity
9.8 Critical
CVSS 3.1: 7.5 (GHSA)
Exploitation
EPSS 2%
Type
CWE-915Improperly Controlled Modification of Dynamically-Determined Object Attributes
CWE-1321Prototype Pollution
Timeline
Published2 Sep 2026
Updated2 Sep 2026
First seen6 Mar 2026
Monitor software like this
Free during beta