Description
A prototype pollution in the lib.deep function of @ndhoule/defaults v2.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.0.1
References
Related Issues
- deep-defaults vulnerable to prototype pollution - CVE-2021-25944
- @intlify/shared Prototype Pollution vulnerability - CVE-2024-52810
- vxe-table prototype pollution - CVE-2024-57080
- @intlify/shared Prototype Pollution vulnerability - vue-i18n - CVE-2024-52810
You might also like:
- Tags:
- npm
- @ndhoule/defaults
Anything's wrong? Let us know Last updated on February 06, 2025


