CVE-2026-104852High· 8.2▾ TwilightGraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 12.0.1, the GraphQL Tools utils package's mergeDeep function follows inherited properties while recursively merging source objects and does n…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 12.0.1, the GraphQL Tools utils package's mergeDeep function follows inherited properties while recursively merging source objects and does not exclude proto, constructor, or prototype keys. An unauthenticated GraphQL client can alias fields to those names so responses from two subgraphs collide during ordinary supergraph result merging, causing mergeDeep to traverse Object and Function prototypes and overwrite Function.prototype.call with a subgraph-supplied value. This breaks subsequent requests in the process until restart. This issue is fixed in version 12.0.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
@graphql-tools/utils <= 12.0.0Patched in:
@graphql-tools/utils 12.0.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103918Medium· 6.5oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards
CVE-2026-104849Critical· 9.5Tinypool is a minimal Node.js worker thread pool implementation
CVE-2026-104848Critical· 9.5Tinypool is a minimal Node.js worker thread pool implementation
CVE-2026-104183Medium· 5.1stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint
CVE-2026-102992Critical· 9.2piscina is a node.js worker pool implementation
CVE-2026-102600High· 7.5Socket.IO enables bidirectional and low-latency communication for every platform