Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6594

25
FAUCET Score

CVE-2026-6594 is a prototype pollution vulnerability affecting brikcss merge library versions up to 1.3.0. The flaw allows attackers to manipulate the __proto__, constructor.prototype, or prototype properties, resulting in improperly controlled modification of object prototype attributes. This vulnerability can be exploited remotely without authentication or user interaction, making it broadly accessible. The vulnerability carries a CVSS score of 7.3 (HIGH) with a network-based attack vector and low attack complexity. Successful exploitation could result in limited impacts across confidentiality, integrity, and availability. The EPSS score of 0.0004 indicates minimal real-world exploitation probability compared to other disclosed vulnerabilities. There is currently no evidence of active exploitation, and the vulnerability has not been designated as a known exploited vulnerability (KEV) by CISA. Community attention remains low, as reflected by its inactive status on threat tracking lists. The vendor was contacted early but provided no response regarding remediation efforts. Organizations using brikcss merge should consider upgrading beyond version 1.3.0 when patches become available.

Impacted Technologies

VendorProductVersion(s)CPE
BrikcssMerge
1.0, 1.1, 1.2, 1.3.0CNA affected

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.34%
Probability of exploitation in next 30 days
EPSS Percentile
26.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0034 is in the 8th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

npmGHSA-3jc6-6r48-v6qfmedium

Deep Merge is Vulnerable to Prototype Pollution Through Lack of Sanitization

Apr 20, 2026

References

github.com / sudo-secure/security-research/blob/main/brikcss-merge/prototype-pollution/PoC.md
vuldb.com / submit/791805
vuldb.com / vuln/358229
vuldb.com / vuln/358229/cti