Vulnerabilities/

Deep Merge is Vulnerable to Prototype Pollution Through Lack of Sanitization

Severity:
Medium

Description

A Prototype Pollution vulnerability was determined in brikcss merge up to 1.3.0. Executing a manipulation of the argument proto/constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@brikcss/merge
Anything's wrong? Let us know Last updated on April 23, 2026