Description
merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’)
Recommendation
Update the @viking04/merge package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.2
- Patched version(s): 1.0.2
References
Could your website be exposed too?
SmartScanner can check your website for merge vulnerable to Prototype Pollution and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Prototype Pollution in merge-change - CVE-2021-23421
- json-schema is vulnerable to Prototype Pollution - CVE-2021-3918
- jszip Vulnerable to Prototype Pollution - CVE-2021-23413
- rollbar vulnerable to Prototype Pollution in merge() - CVE-2025-62517
You might also like:
See something that needs correcting? Let us knowUpdated January 29, 2023


