Vulnerabilities/

ts-deepmerge before 2.0.2 vulnerable to Prototype Pollution

Severity:
High

Description

The package ts-deepmerge before version 2.0.2 is vulnerable to Prototype Pollution due to missing sanitization of the merge function.

Recommendation

Update the ts-deepmerge package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ts-deepmerge
Anything's wrong? Let us know Last updated on January 27, 2023