Prototype Pollution in deep-extend
Critical severity
GitHub Reviewed
Published
Oct 9, 2018
to the GitHub Advisory Database
•
Updated Feb 12, 2025
Description
Published to the GitHub Advisory Database
Oct 9, 2018
Reviewed
Jun 16, 2020
Last updated
Feb 12, 2025
Versions of
deep-extend
before 0.5.1 are vulnerable to prototype pollution.Recommendation
Update to version 0.5.1 or later.
References