Vulnerabilities/

ts-deepmerge: Prototype Method Override leads to DoS

Severity:
Medium

Description

Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf).

Recommendation

Update the ts-deepmerge package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ts-deepmerge
Anything's wrong? Let us know Last updated on June 19, 2026