GHSA-x7q7-fchv-8h2jHighCVSS 8.2

@ranfdev/deepobj has a Prototype Pollution vulnerability

Published
May 14, 2026
Last Modified
June 9, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Prototype pollution is possible when property paths contain __proto__/constructor/prototype. The property path must not be exposed as user input.

🎯 Affected products1

  • npm/@ranfdev/deepobj:<= 1.0.2

🔗 References (3)