GHSA-gcqx-w48m-w2h4HighCVSS 7.5

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject()...

Published
September 18, 2026
Last Modified
September 18, 2026

🔗 CVE IDs covered (1)

📋 Description

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without own-property checks.

🔗 References (6)