Vulnerabilities/

@tanstack/form-core prototype pollution

Severity:
High

Description

A prototype pollution in the lib.mutateMergeDeep function of @tanstack/form-core v0.35.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Recommendation

Update the @tanstack/form-core package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@tanstack/form-core
Anything's wrong? Let us know Last updated on February 20, 2025