Vulnerabilities/

@zag-js/core prototype pollution

Severity:
High

Description

A prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Recommendation

Update the @zag-js/core package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@zag-js/core
Anything's wrong? Let us know Last updated on March 19, 2025