deepmerge-ts
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting deepmerge-tspage 1 of 1
- CVE-2022-24802HIGHCVSS 8.1EG 8.1✓ Fixed in 4.0.22022-04-01
deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). This issue has been patched in ver…
- CVE-2026-40345HIGHCVSS 8.2EG 8.2✓ Fixed in 8.0.02026-08-17
deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the deepmerge, deepmergeCustom, deepmergeInto, and deepmergeIntoCustom APIs do not track visited objects or object pairs wh…
Check whether deepmerge-ts is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for deepmerge-ts CVEs against the assets you own.
Start Free Scan →