CVE-2026-6594 is a prototype pollution vulnerability affecting brikcss merge library versions up to 1.3.0. The flaw allows attackers to manipulate the __proto__, constructor.prototype, or prototype properties, resulting in improperly controlled modification of object prototype attributes. This vulnerability can be exploited remotely without authentication or user interaction, making it broadly accessible. The vulnerability carries a CVSS score of 7.3 (HIGH) with a network-based attack vector and low attack complexity. Successful exploitation could result in limited impacts across confidentiality, integrity, and availability. The EPSS score of 0.0004 indicates minimal real-world exploitation probability compared to other disclosed vulnerabilities. There is currently no evidence of active exploitation, and the vulnerability has not been designated as a known exploited vulnerability (KEV) by CISA. Community attention remains low, as reflected by its inactive status on threat tracking lists. The vendor was contacted early but provided no response regarding remediation efforts. Organizations using brikcss merge should consider upgrading beyond version 1.3.0 when patches become available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Brikcss | Merge | 1.0, 1.1, 1.2, 1.3.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.