Vulnerability library
Security checkJuly 31, 2026

@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A prototype pollution vulnerability exists in @phun-ky/defaults-deep prior to version 2.0.5.

The library recursively merged user-supplied objects without filtering unsafe property names such as __proto__, constructor, and prototype. An attacker able to supply crafted input could cause properties to be written to Object.prototype, resulting in prototype pollution affecting all objects within the running process.

Recommendation

Update the @phun-ky/defaults-deep package to the latest compatible version. Followings are version details:

  • Affected version(s): < 2.0.5
  • Patched version(s): 2.0.5

References

Could your website be exposed too?

SmartScanner can check your website for @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 31, 2026