Prototype Pollution in merge-deep
High severity
GitHub Reviewed
Published
Jul 26, 2018
to the GitHub Advisory Database
•
Updated Sep 7, 2023
Description
Published to the GitHub Advisory Database
Jul 26, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 7, 2023
Versions of
merge-deep
before 3.0.1 are vulnerable to prototype pollution via merging functions.Recommendation
Update to version 3.0.1 or later.
References