Description
The utilities function in all versions of the merge-object node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.0.0
References
Related Issues
- Prototype Pollution in merge-options - CVE-2018-3752
- axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge - CVE-2026-44495
- Prototype pollution in controlled-merge - CVE-2020-28268
- axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions - CVE-2026-44490
You might also like:
- Tags:
- npm
- merge-object
Anything's wrong? Let us know Last updated on January 09, 2023


