Deep Merge is Vulnerable to Prototype Pollution Through Lack of Sanitization
- Severity:
- Medium
Description
A Prototype Pollution vulnerability was determined in brikcss merge up to 1.3.0. Executing a manipulation of the argument proto/constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.3.1
References
Related Issues
- axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge - CVE-2026-44495
- @pdfme/common vulnerable to to XSS and Prototype Pollution through its expression evaluation - CVE-2025-53626
- @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging - CVE-2026-54737
- CASL Ability is Vulnerable to Prototype Pollution - CVE-2026-1774
You might also like:
- Tags:
- npm
- @brikcss/merge
Anything's wrong? Let us know Last updated on April 23, 2026


